Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας

Υφυπουργείο Έρευνας, Καινοτομιας Και Ψηφιακής Πολιτικής

Ανακοινώνεται η έναρξη Δημόσιας Διαβούλευσης της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη (ΤΝ), που εκπονήθηκε από την Εθνική Εξειδικευμένη Επιτροπή για την Τεχνητή Νοημοσύνη (National AI Taskforce), η οποία συστάθηκε με Απόφαση του Υπουργικού Συμβουλίου (αρ. απόφασης 97.538, ημερ. 22/1/2025), υπό την προεδρία του Επικεφαλής Επιστήμονα για Έρευνα, Καινοτομία και Τεχνολογία, και με έντεκα (11) μέλη προερχόμενα από τον δημόσιο και ιδιωτικό τομέα, την ακαδημαϊκή και ερευνητική κοινότητα.

Η Στρατηγική αποτελεί το ολοκληρωμένο εθνικό πλαίσιο πολιτικής της Κυπριακής Δημοκρατίας για την αξιοποίηση των δυνατοτήτων της ΤΝ, με όραμα, έως το 2032, η Κύπρος να αναγνωρίζεται ως ο αξιόπιστος κόμβος ΤΝ στην Ανατολική Μεσόγειο, ως μια αξιόπιστη ευρωπαϊκή δικαιοδοσία για την παροχή υπηρεσιών που αξιοποιούν την ΤΝ και ως γέφυρα μεταξύ της Ευρωπαϊκής Ένωσης και των γειτονικών περιοχών.

H Στρατηγική αναπτύσσεται γύρω από 8 αλληλένδετους Εθνικούς Στρατηγικούς Στόχους:

  1. Καθιέρωση της Κύπρου ως αξιόπιστης δικαιοδοσίας για την ΤΝ.
  2. Αύξηση της εθνικής παραγωγικότητας μέσω της υπεύθυνης υιοθέτησης της ΤΝ.
  3. Ανάπτυξη ενός ισχυρού και χωρίς αποκλεισμούς οικοσυστήματος ΤΝ.
  4. Μετασχηματισμό των δημόσιων υπηρεσιών μέσω της αξιοποίησης της ΤΝ.
  5. Ανάπτυξη, προσέλκυση και διατήρηση δεξιοτήτων και ανθρώπινου δυναμικού στον τομέα της ΤΝ.
  6. Διασφάλιση ασφαλών, κυρίαρχων και διαλειτουργικών δεδομένων και υποδομών.
  7. Εδραίωση ισχυρής διακυβέρνησης, δεοντολογίας και λογοδοσίας σε κάθε χρήση της ΤΝ.
  8. Ανάπτυξη κυρίαρχων εθνικών δυνατοτήτων μέσω στρατηγικών συνεργασιών.

Το προσχέδιο της Εθνικής Στρατηγικής για την ΤΝ βρίσκεται αναρτημένο πιο κάτω και καλούνται όλοι οι ενδιαφερόμενοι να υποβάλουν τα σχόλια, εισηγήσεις και παρατηρήσεις τους μέσω της πλατφόρμας «η-Διαβούλευση» μέχρι την 31η Αυγούστου 2026.

Όλες οι απόψεις και προτάσεις που θα υποβληθούν θα αξιολογηθούν και, όπου κριθεί σκόπιμο, θα ενσωματωθούν στην τελική έκδοση της Στρατηγικής.

Παράκληση όπως τα σχόλια γίνονται σύμφωνα με την πιο κάτω δομή:

Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο

Σχόλιο / Εισήγηση

Αιτιολόγηση σχολίου / Εισήγησης

Για οποιεσδήποτε διευκρινίσεις σχετικά με τη διαδικασία της διαβούλευσης, μπορείτε να επικοινωνείτε με το Υφυπουργείο Έρευνας, Καινοτομίας και Ψηφιακής Πολιτικής.

Όνομα λειτουργού δημόσιας διαβούλευσης: Ανδρέας Αδαμίδης
Email: aadamidis@dmrid.gov.cy
Τηλέφωνο: 22 691945 / 22 309453
Επιστήμη και Τεχνολογία
Κυβέρνηση και Δημόσιος Τομέας
Κείμενο Στρατηγικής
  • Ανοικτή
  • Αναρτήθηκε
    20 Ιούλ 2026 @ 0:00
  • Ανοικτή σε σχόλια ως
    31 Αυγ 2026 @ 23:50
  • 89 σχόλια

83 Σχόλια

  1. Excellent and highly ambitious document! However, as a practicing IT specialist living and working in Cyprus, I would like to offer some pragmatic, technical adjustments to ensure this Strategy translates into successful, resilient, and highly impactful implementation.
    To make this feedback easy to process for the working group, I have structured my suggestions into two logical categories: Horizontal Enablers and Sector-Specific Initiatives.

    SECTION 1 – HORIZONTAL ENABLERS AND INFRASTRUCTURE
    1.1 – G-Cloud Migration Timeline and Operational Stress-Testing [Reference: Strategy Document, Section 3.4 “AI Adoption Across Government” and Annex C “Government and Public Sector”, Page 62]
    THE BLUEPRINT TIMELINE: The roadmap currently schedules G-Cloud architecture design completion for December 2026, with the migration of the first three pilot applications completed by March 2027.
    THE OPERATIONAL CHALLENGE: A three-month window to migrate legacy government systems into a brand-new hybrid cloud environment is an extremely high-risk schedule that even agile private corporations rarely manage. A rushed sprint here poses severe architectural, operational, and security risks, including database integration failures, service downtime, and security vulnerabilities.
    THE PROPOSED ADJUSTMENT: I suggest extending the pilot migration window from three to nine months, targeting September 2027. We should explicitly mandate that these first three applications must consist of non-critical, static datasets, such as public archival databases. This will allow the team to thoroughly stress-test G-Cloud’s security baselines and API Fabric before any high-risk personal or transactional databases are touched.
    1.2 – AI Talent Target Segmentation (Class-A vs. Class-B) [Reference: Strategy Document, Section 3.6 “Talent, Skills and Workforce Transformation” and Annex C “Education and Human Capital Development – FutureAI CY”, Page 80]
    THE KPI IN THE BLUEPRINT: The strategy aims to train 3,000 AI professionals by 2032 through stackable micro-credentials of 5 to 15 ECTS (approx. 150-450 hours of study).
    THE OPERATIONAL CHALLENGE: Grouping high-end ML engineers, no-code creators, prompt writers, and basic public sector users under a single target of 3,000 professionals obscures the real engineering gap. A 150-hour course can train an administrator to use an AI interface, but it cannot produce an engineer capable of fine-tuning LLMs, managing security, or preventing model hallucinations in sensitive sovereign systems.
    THE PROPOSED ADJUSTMENT: Subdivide the 3,000-talent target into two distinct tracks. Class A should cover core ML Engineers and AI Architects with a dedicated target of at least 15% (450+ specialists). Class B should cover No-code Creators and Business Users for the remainder of the training pool. Funding under the FutureAI CY program should prioritize rigorous, long-term engineering tracks to build the actual technical capacity required for digital sovereignty.
    1.3 – “Zero-AI Baseline Test” to Prevent AI-Washing in Public Procurement [Reference: Strategy Document, Section 3.1.2 “Value-driven deployment”, Page 19 and Annex C, Page 61-62]
    THE TARGET IN THE BLUEPRINT: Flagship public sector initiatives, such as the Digital Company 2.0 registration processes or the Skills and Labour Market Platform (NASO), are currently categorized under the core AI portfolio.
    THE OPERATIONAL CHALLENGE: Aggregating job postings or automating basic business registrations are standard, deterministic database tasks. They are 100% solvable using secure relational databases, clean API integrations, and standard BI dashboards. Introducing probabilistic AI/LLMs where absolute, auditable accuracy is required introduces unnecessary risks of “hallucinations” and inflates software vendor quotes by 3x to 5x.
    THE PROPOSED ADJUSTMENT: Integrate a mandatory Zero-AI Baseline Test within the ApplyAI project selection framework. Before approving AI-specific budgets, the National AI Authority must verify if the problem can be solved with high accuracy using classical automation, secure APIs, and relational databases. If yes, the project must be routed to standard digital transformation budgets (DMRID), preserving scarce AI-expert hours and GPU capacities for truly complex cognitive workloads (such as court transcription or medical image diagnostics).

    SECTION 2 – SECTORAL INITIATIVES AND COMPLIANCE
    2.1 – “Simplified Compliance Sandbox” for Startups and SMEs [Reference: Strategy Document, Section 3.11.2, Page 45 and Annex C “Government and Public Sector – Private Companies”, Page 60]
    THE CONSTRAINT IN THE BLUEPRINT: To access state-subsidized grants, public datasets, or the national GPU cloud, private companies must share their ethical AI strategies and adhere to rigorous ISO 42001 and ISO 27001 standards.
    THE OPERATIONAL CHALLENGE: Enforcing formal ISO compliance on early-stage local startups and SMEs (with under 1 million Euros in turnover) creates an insurmountable financial and bureaucratic barrier, stifling local tech entrepreneurship before it can take root.
    THE PROPOSED ADJUSTMENT: Implement a Simplified Compliance Sandbox for startups and micro-SMEs. Instead of requiring external ISO certification on day one, the Ministry should provide free self-assessment templates, pre-audited compliance checklists, and automatic access to state-subsidized cloud resources. Formal ISO audits should only become mandatory once a startup matures or scales to high-risk public utility deployments.
    2.2 – Establishing Physical IoT Foundations as a Prerequisite for “Destination Digital Twins” [Reference: Strategy Document, Annex C “Tourism and Hospitality”, Page 71-73]
    THE TARGET IN THE BLUEPRINT: The strategy proposes developing complex “Destination Digital Twins” for tourism hubs (Limassol, Ayia Napa) to simulate climate impacts, heatwaves, and resource bottlenecks.
    THE OPERATIONAL CHALLENGE: A true digital twin is a dynamic mathematical model that requires continuous, real-time data streams to be useful. On Cyprus, real-time data streams from existing local utility sensors remain highly fragmented, siloed across disparate municipalities, and lack unified standards and API integrations. Building predictive AI simulations without clean, real-time data pipelines is mathematically impossible and risks wasting budgets on static 3D maps that offer limited operational utility.
    THE PROPOSED ADJUSTMENT: Postpone the modeling phase of “Digital Twins” to Phase 2 (post-2028). Reallocate Phase 1 budgets to co-fund the physical rollout of IoT sensor networks (smart water and electricity meters for hotels, traffic sensors) and to establish a Unified National IoT and Sensor Data Standard. Building this solid physical data foundation is a mandatory prerequisite before any intelligent predictive simulation can be successfully deployed.

  2. The comments address three key dimensions of the Cyprus National AI Strategy 2032: (1) Governance, (2) Standardisation and Assurance, and (3) Technological and Security Sovereignty.
    COMMENTS
    1. National AI Authority: Considering the evolving AI landscape and the strategic, cross-sectoral and security-sensitive implications of AI, the effective implementation of the Strategy should consider the establishment or designation of a strong and appropriately independent National AI Authority. Such an Authority could serve as the central institutional mechanism for coordinating the implementation of the Cyprus National AI Strategy 2032, while ensuring alignment with the National Interest and the broader European regulatory and policy framework. Given the strategic and cross-sectoral nature of its mandate, the Authority should operate under an appropriate legal framework, with clearly defined responsibilities, powers, accountability mechanisms and interfaces with the existing competent authorities of the Republic. Its governance and modus operandi should reflect the strategic importance, security requirements and institutional safeguards associated with national-level authorities dealing with critical and security-sensitive matters, while avoiding duplication or interference with the statutory responsibilities of existing authorities. The National AI Authority could provide the central governance and coordination layer required to align national activities across the Research, Innovation, Development and Deployment (R&I&D&D) lifecycle of AI. Its overarching purpose should be to ensure that AI capabilities are researched, developed, acquired and deployed in a trusted, secure, resilient and sovereign manner, while protecting people, critical assets, strategic resources and national data; managing systemic risks, technological dependencies and supply-chain exposure; and safeguarding the sovereignty, resilience, security and long-term strategic interests of the Republic of Cyprus. Given the strategic significance and horizontal responsibilities, its institutional positioning should reflect a level of authority and access commensurate with other relevant national security and strategic authorities of the Republic.
    (A) Proposed amendment to the Strategy: The establishment, designation, mandate and institutional positioning of a National AI Authority should be considered and discussed at the appropriate political and governmental level, taking into account the existing national institutional architecture and the applicable EU AI governance framework.

    2. Standardisation and AI Assurance: Standardisation should constitute an integral component of the National AI Strategy and its implementation framework. This is critical for establishing the necessary levels of trust, interoperability, security, conformity and assurance across national AI activities. National participation in European and international AI standardisation is also strategically important for ensuring that Cyprus can both implement emerging standards and contribute to their development, particularly in areas related to trustworthy AI, cybersecurity, data, cloud/edge computing, AI assurance and conformity assessment. The contribution of the national standardisation bodies and relevant national experts of the Republic of Cyprus should therefore be explicitly incorporated into the governance and implementation mechanisms of the Strategy.
    (A) Proposed amendment to the Strategy: Section 3.3.1 – Governance Structure should include explicit provisions defining the role of the relevant national standardisation entities and mechanisms for integrating European and international standards into the national AI governance and assurance framework.

    3. Chips – AI Infrastructure – Quantum Security: The strategic link between Section 3.7.5, “Integration with EuroHPC and the European AI Factory Ecosystem,” and the European semiconductor and chips ecosystem is fundamental (also the Quantum security part). AI capabilities increasingly depend on advanced processors, AI accelerators, heterogeneous computing architectures, chiplets and specialised semiconductor technologies. At the same time, a gap remains between chip-level security engineering and AI infrastructure security. Addressing AI infrastructure security exclusively at the software, platform or application layers would therefore leave an increasingly important part of the AI technology stack insufficiently addressed. Specific provisions should consequently strengthen the integration of chip and chiplet security engineering into national AI activities, including security-by-design, hardware roots of trust, trusted execution, supply-chain assurance, hardware-level resilience, secure lifecycle management and advanced semiconductor security engineering. As AI capabilities and infrastructures continue to expand, the convergence of AI, high-performance computing and trusted semiconductor technologies is becoming strategically important for the security, resilience and technological sovereignty of European and national AI infrastructures. The National AI Strategy should therefore recognise the hardware–software continuum as a fundamental dimension of AI sovereignty, addressing not only algorithms, data, software and computing capacity, but also the trusted semiconductor technologies on which those capabilities ultimately depend.
    (a) Proposed amendment to the Strategy:
    (A) Section 3.7.5 should include provisions strengthening the connection between AI infrastructure and the chips/chiplet ecosystem supported by tangible implementation actions. These could include, inter alia: (i) strengthening the participation of the Republic of Cyprus and its research and industrial ecosystem in relevant Chips Joint Undertaking (Chips JU) programmes and calls, (ii) supporting national R&D and investment in semiconductor, chiplet, hardware-security and AI-accelerator technologies, (iii) promoting participation in European semiconductor and AI infrastructure value chains, (iv) developing national capabilities in trusted and secure AI hardware, (v) connecting semiconductor research and innovation with EuroHPC, AI Factories and national AI infrastructure initiatives, (vi) supporting the development of a national ecosystem capable of addressing the full AI technology stack, from trusted hardware and computing infrastructure to data, models, applications and services.
    (B) AI, Cybersecurity and Quantum Security: Particular consideration should also be given to the convergence of AI, cybersecurity, semiconductor technologies (chip/chiplet) and quantum security. The development of increasingly powerful AI and HPC infrastructures introduces new security dependencies and systemic risks, including those associated with future quantum capabilities and the transition towards post-quantum and quantum-secure technologies. The Strategy should therefore establish a clear connection between the development of national AI capabilities, the chips/chiplet ecosystem, cybersecurity and quantum security, promoting security-by-design across the complete technology stack. This should include consideration of post-quantum cryptography, crypto-agility, trusted hardware, secure key management, hardware-assisted security, quantum-safe migration and, where appropriate, complementary quantum-security technologies. Given the highly cross-cutting nature of these domains, consideration could also be given to the idea of a national capability or coordination function at the intersection of AI, Cybersecurity, Quantum Security and Trusted Semiconductor Technologies. Such a capability could support the national AI ecosystem, monitor technological and security developments, coordinate relevant R&D and innovation activities, strengthen participation in European initiatives, and provide specialised technical expertise to competent national authorities and stakeholders and support the security of Critical Assets of the Republic. The appropriate institutional form i.e Centre of Excellence, specialised competence centre, or another suitable mechanism, should be subject to further analysis, taking into account existing national structures, competencies and European initiatives, with the objective of avoiding duplication while closing identified strategic and technological capability gaps.

  3. HLTF-29. Publish an accessible, version-controlled and authoritative final Strategy
    Strategy reference: Whole document; Annexes G–H
    Comment type: Transparency / drafting / accessibility
    Comment and implementation risk. The 101-page document contains inconsistent body names, undefined frameworks, incomplete citations, drafting errors and a bibliography with no standardisation documents. It is available in English despite being a national public-policy instrument. A strategy that will guide procurement and compliance must have a reliable authoritative version, source hierarchy and amendment history.
    Requested amendment. Complete legal and technical editorial review; publish Greek and English versions, accessible formats, source register and change log.
    Proposed text for insertion or replacement
    Publication, version control and accessibility. Before adoption, the Strategy shall undergo legal, technical, linguistic and accessibility review. The Republic shall publish authoritative Greek and English versions, an accessible HTML version, a concise citizen summary and machine-readable annexes. Each version shall show approval authority, approval date, version number, change history and next review date. Defined terms and institutional names shall be consistent. Citations shall identify complete titles, dates, versions and stable links; primary law and official materials shall take priority over media, vendor and unsourced benchmark claims. Annex H shall include applicable EU and national law, CYS’s legal basis, CEN-CENELEC/ETSI work and relevant ISO/IEC standards. A public correction process shall address errors discovered after adoption.

    4. Cross-cutting implementation package
    The following package converts the detailed amendments into a practicable delivery sequence. Dates run from final adoption of the Strategy, not from the consultation draft.
    Before final adoption
    1. Complete legal and technical editorial review; update the AI Act timetable; remove or condition initiatives that lack legal authority.
    2. Prepare the concordance with the final national AI implementing law and a definitive governance/RACI schedule.
    3. Publish the methodology, comparator selection, evidence register and consultation-response report.
    4. Reconcile all KPIs, dates, body names and glossary terms; produce authoritative Greek and English versions.
    Within 90 days
    1. Publish the Digital Strategy 2020–2025 transition evaluation and current digital/data/cloud/interoperability baseline.
    2. Agree cooperation protocols among the Deputy Ministry, competent AI authorities, CYS, the accreditation function, sector regulators and data/cyber authorities.
    3. Create the legal-dependency register, public-sector AI inventory and standards roadmap.
    4. Issue interim approval gates for legality, FRIA/DPIA, security, procurement, data and architecture.
    Within 120–180 days
    1. Publish model AI tender and contract schedules, sector implementation dossiers and a national sandbox framework.
    2. Cost the delivery portfolio; assign owners; define benefits, stop/scale criteria, independent assurance and evaluation.
    3. Launch SME/startup clinics, compute/testing support and standards-participation funding.
    4. Complete infrastructure criticality, concentration, energy, water, continuity and exit assessments.
    Annually
    1. Publish a consolidated report on spending, outcomes, rights impacts, incidents, complaints, standards, market concentration, energy/water and stopped initiatives.
    2. Update the law-and-standards register and sector profiles; record every material change to targets, scope or governance.
    3. Commission independent evaluation and parliamentary/public scrutiny of high-impact public-sector uses.
    4.1 Conditions before the first transformational procurements
    Minimum launch gate
    No major AI tender should be issued merely to meet the draft eight-month timetable. The minimum package is: named accountable owner; lawful purpose and AI Act classification; current data and system architecture; integrated rights/security assessment; budget and benefits case; standards profile; market and concentration analysis; complete contract schedules; independent assurance route; incident and evidence plan; portability and funded exit; and published decision to proceed.
    4.2 Proposed annual assurance statement
    The accountable National AI Authority should publish a signed annual statement confirming which commitments were delivered, which were not, material departures from law or standards, unresolved high risks, total expenditure, realised benefits, major incidents and complaints, concentration exposures, and the actions required for the following year. The statement should be subject to independent audit or evaluation appropriate to each claim; it should not be called a conformity certificate unless issued under a defined lawful scheme.

    Annex A. Legal and regulatory map
    This is a strategy-level map, not an exhaustive statement of applicable law. Each initiative requires a fact-specific legal assessment and review of the current consolidated text of the relevant instrument.
    A.1 AI governance. The principal instruments are Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, together with the final Cyprus implementing law. Strategy implementation should address classification, duties by role, authorities, sandboxes, the database, enforcement and timing.
    A.2 Data and privacy. The relevant framework includes the GDPR, Data Governance Act, Data Act, Open Data Directive, EHDS and ePrivacy rules. Strategy implementation should address lawful access, roles, purpose, data rights, data spaces and health data.
    A.3 Cyber and resilience. The principal instruments are NIS2, the CER Directive, the EU Cybersecurity Act, the Cyber Resilience Act and DORA. Strategy implementation should address criticality, incident response, supply-chain requirements and operational resilience.
    A.4 Identity and evidence. The relevant framework includes eIDAS, as amended by Regulation (EU) 2024/1183, together with national evidence and procedural law. Strategy implementation should address identity, signatures, time stamps, ledgers, archiving and admissibility.
    A.5 Intellectual property and confidentiality. The relevant instruments include the DSM Copyright Directive, Database Directive, Trade Secrets Directive and the AI Act GPAI duties. Strategy implementation should address training data, text-and-data-mining reservations, provenance, licences and confidential inputs.
    A.6 Liability and consumers. The relevant framework includes Directive (EU) 2024/2853, the GPSR, the consumer acquis and national contract and tort law. Strategy implementation should address software and AI product liability, disclosure, remedies and allocation of contractual responsibility.
    A.7 Markets and procurement. The relevant framework includes the 2014 procurement directives, State-aid law, the DMA and sector-specific competition law. Strategy implementation should address neutral specifications, proportionality, contestability, subsidies and the avoidance of lock-in.
    A.8 Sector overlays. Sector-specific requirements may arise under the MDR/IVDR, MiCA, the DLT Pilot Regime, the AML package, machinery legislation and other applicable sectoral law. Strategy implementation should address product, financial, professional and safety authorisations.
    A.9 Fundamental rights. The relevant framework includes the Cyprus Constitution, the EU Charter, the ECHR, and applicable equality, accessibility and child-rights law. Strategy implementation should address necessity, proportionality, fair process, reasons, human review and effective remedy.

    Annex B. Standards architecture
    Standards should be selected by legal role, intended use, system risk and sector. The references below are illustrative anchors for the national roadmap. Edition status, adoption as a European or Cyprus standard, and any OJEU citation must be checked at the time of use.
    B.1 Management and governance. Illustrative standards routes include ISO/IEC 42001:2023 and ISO/IEC 38507:2022. These should be used for organisational systems and governing-body guidance and should not be treated as automatically establishing conformity with the AI Act.
    B.2 Risk and impact. Illustrative standards routes include ISO/IEC 23894:2023 and ISO/IEC 42005:2025. These should be used for risk-management and impact-assessment guidance.
    B.3 Lifecycle and data. Illustrative standards routes include ISO/IEC 5338:2023 and the ISO/IEC 5259 series. These should be used for lifecycle processes and data-quality governance and processes.
    B.4 Security. ISO/IEC 27001:2022 and relevant controls from the ISO/IEC 27000 series provide illustrative standards routes for information-security management and selected cloud and privacy controls.
    B.5 AI Act harmonisation. CEN-CENELEC JTC 21 deliverables should be monitored for adoption and OJEU citation. A presumption of conformity should be attributed only within the scope that is actually cited.
    B.6 Distributed systems. Relevant work from ISO/TC 307, CEN/CLC JTC 19 and ETSI should be considered for DLT terminology, architecture, governance, interoperability and sector application.
    B.7 Forensic readiness. Relevant ISO/IEC digital-evidence standards and emerging AI/DLT work should be considered for evidence identification, preservation, analysis, auditability and incident reconstruction.

    B.8 Proposed national standards mechanism
    CYS should convene a funded National AI Standards Roadmap with public authorities, industry, startups, academia, professions, workers, consumers and civil society. It should maintain a standards inventory, gap analysis, national positions, delegation support, training plan, procurement profiles and annual adoption report. Cyprus should contribute early to European and international work – including AI/DLT convergence and forensic evidence – while avoiding claims that work in development already constitutes a published or harmonised standard.

    Annex C. Authoritative sources
    Principal sources reviewed or relied upon. Online sources were checked on 30 August 2026. The final Strategy should cite the current consolidated legal text and current edition/status of standards at implementation.
    1. Cyprus National AI Strategy 2032 – consultation text (101 pages)
    2. Draft Cyprus law implementing Regulation (EU) 2024/1689 – consultation opened 16 August 2026
    3. CYS – official role as Cyprus’s National Standardisation Body
    4. Law 156(I)/2002 on standardisation, accreditation and technical information (copy reviewed)
    5. Cyprus National Digital Strategy 2020–2025
    6. Cyprus National Digital Decade Strategic Roadmap – 2024 revision
    7. European Commission – Cyprus 2026 Digital Decade Country Report
    8. Regulation (EU) 2024/1689 (Artificial Intelligence Act)
    9. Regulation (EU) 2026/1744 (Digital Omnibus on AI)
    10. European Commission – current AI Act framework and application timeline
    11. European Commission – standardisation under the AI Act
    12. CEN-CENELEC – JTC 21 Artificial Intelligence
    13. ISO/IEC 42001:2023 – AI management systems
    14. ISO/IEC 23894:2023 – AI risk management
    15. ISO/IEC 42005:2025 – AI system impact assessment
    16. ISO/IEC 5338:2023 – AI system lifecycle processes
    17. ISO/IEC 38507:2022 – governance implications of AI
    18. ISO/IEC 5259-5:2025 – data quality governance for analytics and ML
    19. Regulation (EU) 2016/679 (GDPR)
    20. Regulation (EU) 2022/868 (Data Governance Act)
    21. Regulation (EU) 2023/2854 (Data Act)
    22. Regulation (EU) 2025/327 (European Health Data Space)
    23. Directive (EU) 2022/2555 (NIS2)
    24. Directive (EU) 2022/2557 (critical entities resilience)
    25. Regulation (EU) 2024/2847 (Cyber Resilience Act)
    26. Regulation (EU) 2024/1183 (European Digital Identity Framework / eIDAS amendment)
    27. Directive (EU) 2019/790 (copyright in the Digital Single Market)
    28. Directive (EU) 2024/2853 (liability for defective products)
    29. EU Charter of Fundamental Rights, Article 47
    30. European Commission – Better Regulation

    Document basis and limitations
    This submission is a public-policy contribution based on the consultation materials supplied and sources available at the review cut-off. It does not constitute client-specific legal advice, a conformity assessment or a certification. References to proposed Cyprus legislation are to consultation drafts and must be updated against the enacted text. References to standards do not reproduce their copyrighted content and do not imply that every listed standard is applicable to every AI system.

    THE HYBRID LAWTECH FIRM
    empowered by Christiana Aristidou LLC
    Submission focus: Law, regulation, standards, emerging technologies, startups and responsible innovation
    Prepared for the public consultation on the Cyprus National AI Strategy 2032. Submission date: 30 August 2026. Consultation deadline: 31 August 2026.

  4. PUBLIC CONSULTATION
    SUBMISSION
    Cyprus National AI Strategy 2032
    Legal, regulatory, policy and implementation amendments
    Submitted by: THE HYBRID LAWTECH FIRM, empowered by Christiana Aristidou LLC
    Consultation: National AI Strategy of the Republic of Cyprus to 2032
    Consultation deadline: 31 August 2026
    Submission date: 30 August 2026
    Review cut-off: Law, policy, standards and published consultation material available by 30 August 2026
    Scope: Legal architecture, regulatory coherence, standardisation, public policy, emerging-technology convergence, compliance, procurement, startups and delivery
    Recognition of the Strategy’s strengths
    THE HYBRID LAWTECH FIRM recognises the substantial work undertaken to develop a comprehensive national vision to 2032. The Strategy contains many very positive and forward-looking elements, particularly its commitments to trustworthy and human-centred AI, productivity, skills, research, public-service transformation, secure infrastructure, responsible governance and international cooperation. It gives Cyprus an important platform from which to build. This submission seeks to preserve those strengths and provide the legal, regulatory, standards and delivery architecture needed to make them implementable and internationally credible.
    Bottom line
    The Strategy’s ambition and strong elements should be retained. Before final adoption, however, it needs targeted but material refinement: a current policy baseline; concordance with the draft 2026 national AI implementing law and the enacted framework; clear institutional mandates; accurate treatment of law, standards and assurance; integrated rights, data, cybersecurity, procurement, liability and evidence controls; explicit treatment of technology convergence; and a costed, sequenced delivery plan. Flagship proposals must be reframed wherever a strategy cannot itself create regulatory approvals, EU-wide legal presumptions, judicial powers, certification status, legal equivalence or safe harbours. With these amendments, the Strategy can become a strong, executable foundation for trusted AI in Cyprus.
    Contents
    1. Executive position
    2. Assessment framework
    3. Detailed consultation comments
    4. Cross-cutting implementation package
    Annex A. Legal and regulatory map
    Annex B. Standards architecture
    Annex C. Authoritative sources

    How to use this document
    Section 1 may be pasted into the platform’s general-comment field. Each HLTF entry in Section 3 is self-contained and can be submitted against the identified Strategy section. Proposed wording is drafted for direct insertion or adaptation by the drafting authority.

    1. Executive position
    THE HYBRID LAWTECH FIRM welcomes the substantial work undertaken to develop the Strategy and supports its objective of positioning Cyprus as a trustworthy, innovative and internationally connected jurisdiction for artificial intelligence. The draft contains many valuable and forward-looking elements. It does not yet, however, provide a sufficiently coherent legal and delivery architecture for a national strategy extending to 2032. Its principal weakness is not a lack of ideas or ambition; it is the absence of sufficiently disciplined boundaries between law, policy, standards, certification, institutional power, evidence and implementation.
    The final Strategy should be amended before adoption. In particular, it should no longer state without qualification that it builds on the National Digital Strategy 2020–2025. That strategy had expired before this consultation. The legally and strategically sound response is not to declare the AI Strategy automatically invalid, but to require a published transition evaluation and a live baseline connected to the National Digital Decade Strategic Roadmap and any formally adopted successor instruments.
    The sequencing of national measures also matters. A draft law implementing Regulation (EU) 2024/1689 was placed in public consultation on 16 August 2026 while the Strategy consultation remained open. That Bill identifies competent, notifying, market-surveillance, accreditation and sandbox functions. The final Strategy must therefore be conformed to the enacted national framework. A policy document should not anticipate, duplicate or contradict statutory mandates.
    The Strategy should also treat standardisation as implementation infrastructure, expressly recognise CYS and the national delegation/mirror-committee mechanism, and distinguish voluntary international standards from European harmonised standards cited in the Official Journal. This is essential to make governance, procurement, testing, evidence, interoperability, training and market access operational – not merely aspirational.

    1.1 Text for the general-comment field
    THE HYBRID LAWTECH FIRM, empowered by Christiana Aristidou LLC, recognises the substantial work undertaken to prepare the Cyprus National AI Strategy 2032, welcomes its many positive and forward-looking elements, and supports its ambition. This submission seeks to preserve those strengths while recommending the material amendments needed before final adoption. The Strategy should be converted from a broad catalogue of aspirations into a legally coherent, costed and accountable delivery framework. First, it should replace unqualified reliance on the expired National Digital Strategy 2020–2025 with a published transition evaluation and a current baseline linked to Cyprus’s National Digital Decade Strategic Roadmap and any formally adopted successor policies. Secondly, following publication of the draft national law implementing Regulation (EU) 2024/1689 during this consultation, the final Strategy should include a formal concordance with the enacted law and should distinguish policy coordination from statutory regulation, market surveillance, accreditation, certification, enforcement and regulatory-sandbox functions. Thirdly, it should accurately distinguish binding law, European harmonised standards, other European and international standards, professional credentials and government guidance; recognise CYS and Cyprus’s national delegates; correct the treatment of ISO/IEC 42001; and establish a standards roadmap covering CEN-CENELEC JTC 21, ISO/IEC JTC 1/SC 42, ETSI and relevant DLT, cybersecurity and sector committees. Fourthly, major initiatives should pass integrated legality, fundamental-rights, data-protection, equality, accessibility, security, procurement, competition, liability, evidence and sustainability gates. Claims concerning an ‘AI judge’, EU-wide ownership presumptions through AIREG, AML certificates that enable reliance, pre-certification and international equivalence should be deleted or reframed within applicable law. Finally, the Strategy should address the convergence of AI with blockchain/DLT, smart contracts, digital identity and trust services, IoT, digital twins, cloud-edge/HPC, robotics and cybersecurity through technology-neutral architectures and use-case tests. Delivery should be supported by named owners, budgets, baselines, model procurement clauses, SME pathways, public registers, independent evaluation and an annual legal/standards update. These changes would preserve ambition while materially increasing lawfulness, implementability, investor confidence, public trust and international interoperability.

    1.2 Priority amendments
    1. Legal concordance: Conform governance, powers, sandboxes and enforcement to the final 2026 implementing law.
    2. Current policy baseline: Replace unqualified reliance on the expired 2020–2025 Digital Strategy with an evaluated transition and current roadmap.
    3. Clear legal hierarchy: Separate binding law, harmonised standards, voluntary standards, guidance and aspirational programmes.
    4. Institutional integrity: Publish a RACI and separate sponsor, operator, assurance, accreditation, certification and enforcement functions.
    5. Rights-by-design: Apply integrated legality, FRIA/DPIA, equality, accessibility and remedy gates before public-sector use.
    6. Procurement controls: Adopt mandatory AI tender and contract clauses before launching transformational procurements.
    7. Data governance: Create lawful, federated and documented access rules rather than relying on the metaphor of State ownership.
    8. Critical infrastructure: Map NIS2/CER/CRA duties, concentration risks, continuity, incident reporting and resource constraints.
    9. Convergence: Address AI with DLT, identity, IoT, digital twins, cloud-edge/HPC, robotics, cybersecurity and smart contracts.
    10. Correct flagship claims: Recast AI judge, AIREG, AML certificates, pre-certification and equivalence claims within lawful limits.
    11. SME scale-up: Provide proportionate clinics, test support, templates, compute and procurement access tied to evidence.
    12. Measurable delivery: Cost the portfolio, reconcile KPIs, assign owners and publish independent evaluation and change logs.

    1.3 Overall institutional position
    1. Regulation creates enforceable duties; standards provide common technical and organisational methods; accreditation attests competence of conformity-assessment bodies; certification evaluates against a defined scheme; policy selects public outcomes. The final Strategy should keep these functions separate and deliberately connected.
    2. The Strategy should be technology-neutral but not technology-blind. AI is increasingly embedded in distributed systems. Cyprus can build a defensible niche by combining legal and regulatory capability with active European and international standards participation across AI, DLT and digital evidence.
    3. Public trust will depend less on visionary labels than on visible control: lawful authority, transparent procurement, demonstrable evidence, human accountability, complaint routes, secure and portable infrastructure, and the capacity to stop systems that do not deliver safe public value.

    2. Assessment framework
    This submission reviewed the full Strategy, relevant Cyprus and EU legislation and policy instruments, applicable standardisation materials, the proposed 2026 national AI implementing law, and the public comments available on the consultation platform as at 30 August 2026. Public comments and other consultation materials were used only to identify recurring implementation concerns; the analysis, conclusions and proposed wording are presented independently by THE HYBRID LAWTECH FIRM.
    2.1 Five tests applied
    1. Legality: Is there an identified competence, legal basis, responsible authority, procedural safeguard and route of review?
    2. Regulatory coherence: Does the proposal fit the AI Act as amended, the draft national law, the wider EU digital acquis and sector regulation?
    3. Assurance: Can the claimed outcome be evidenced through standards, testing, audit, conformity assessment, records and independent oversight without confusing their legal effects?
    4. Deliverability: Are the owner, budget, procurement route, dependencies, skills, infrastructure, contract rights, timeline and stop/scale criteria specified?
    5. Future fitness: Does the proposal remain technology-neutral, interoperable, portable, rights-preserving and adaptable to convergence and regulatory change?
    2.2 Four-layer drafting rule
    The Strategy should apply a four-layer drafting rule that clearly distinguishes law, standards, assurance, and policy and delivery.
    Law: EU and Cyprus legislators, together with competent authorities, create duties, powers, procedures, sanctions and legal effects. The Strategy must not imply that a policy statement itself creates a legal power or exemption.
    Standards: CEN, CENELEC and ETSI, together with ISO/IEC and the national standards system, provide consensual specifications and, in defined cases, support conformity. The Strategy must not imply that all standards are mandatory or that compliance with a standard automatically confers a presumption of conformity.
    Assurance: Accreditation bodies, conformity-assessment bodies, auditors and testing facilities assess competence, evidence or conformity within a defined scope. The Strategy must not imply that participation in a sandbox, laboratory, badge or audit is equivalent to regulatory approval.
    Policy and delivery: Government and accountable public bodies set outcomes, fund, procure, coordinate, publish guidance and evaluate. The Strategy must not imply that a proposed programme overrides law, regulators, courts or independent bodies.

    2.3 Principal implementability risks
    1. Institutional risk: overlapping authority names and functions may produce unlawful delegation, duplicated supervision or conflicted assurance.
    2. Reliance risk: users may treat policy labels, registries, credentials or laboratory outputs as legal certification or safe harbour.
    3. Procurement risk: ambitious early tenders may entrench proprietary models, weak audit rights and expensive exit before the governance framework exists.
    4. Rights risk: high-impact public AI may be piloted without a complete legality, necessity, discrimination, accessibility and remedy analysis.
    5. Investment risk: unsupported KPIs and selective international comparisons may weaken credibility with investors, EU institutions and funding evaluators.
    6. Infrastructure risk: cloud/model concentration and energy-water constraints may undermine claimed sovereignty and resilience.
    7. Evidence risk: insufficient provenance and forensic readiness may make incidents, liability and regulatory investigations difficult to reconstruct.

    3. Detailed consultation comments
    Each entry below is drafted to stand alone in the public-consultation platform. References are to the numbered sections and descriptive passages of the consultation version of the Strategy. Proposed text may be inserted directly or adapted while preserving the legal distinction and implementation control identified in the comment.
    HLTF-01. State the legal status of the Strategy and establish a legal-dependency rule
    Strategy reference: Cross-cutting; §§1.1, 2.3.3, 3.3, 3.9.6, 4.3 and Annex A
    Comment type: Legal / governance / drafting
    Comment and implementation risk. The text alternates between policy language, mandatory language and claims that new authorities, registries, audits, certificates and legal presumptions will exist. A strategy may direct policy and spending, but cannot itself create statutory powers, binding duties, judicial procedures, presumptions of ownership, certification status or regulatory equivalence. Leaving the hierarchy unstated exposes ministries, procurers, businesses and citizens to reliance on propositions that may have no legal basis.
    Requested amendment. Insert an interpretation clause that separates law, standards, government policy and proposed initiatives, and make every legally dependent initiative conditional on competence, enactment, funding and impact assessment.
    Proposed text for insertion or replacement
    Legal status and dependencies. This Strategy is a policy framework. It does not of itself create statutory powers, legal duties, regulatory approvals, evidential presumptions, certification status or rights of reliance. References to ‘shall’ bind public bodies only to the extent authorised by applicable law and a duly approved implementation instrument. Each initiative shall be entered in a public legal-dependency register identifying the legal basis, competent authority, required primary or secondary legislation, applicable EU law, standards profile, budget, accountable owner and commencement condition. No initiative affecting rights, market access, supervision, certification or judicial decision-making shall become operational until those conditions are satisfied.

    HLTF-02. Replace the expired digital-strategy foundation with a current, evidenced baseline
    Strategy reference: §2.3.2 and footnote 10; §2.2; Annex A
    Comment type: Strategic / evidence / drafting
    Comment and implementation risk. Section 2.3.2 says the Strategy is aligned with the ‘existing Digital Strategy’, while footnote 10 identifies the National Digital Strategy 2020–2025. That instrument had expired before this 2026–2032 Strategy was consulted. Expiry does not automatically invalidate the AI Strategy, but it makes the asserted foundation incomplete and potentially misleading unless there is an evaluation of delivery, unresolved dependencies and a formal transition to current policy. The document also uses the undefined expression ‘revised Digital Strategy’ elsewhere.
    Requested amendment. Delete the unqualified reliance on the expired instrument. Add a transition and baseline annex linked to the National Digital Decade Strategic Roadmap and any successor digital strategy, with version control and an update trigger.
    Proposed text for insertion or replacement
    Digital-policy baseline. The Strategy takes account of lessons and assets arising from the National Digital Strategy 2020–2025, but does not treat that expired instrument as the current policy foundation. Within 90 days of adoption, the Deputy Ministry shall publish a transition statement that: (a) evaluates the 2020–2025 Strategy against its objectives; (b) identifies completed, continuing, superseded and unimplemented measures; (c) maps dependencies to the current National Digital Decade Strategic Roadmap and any formally adopted successor digital strategy, data strategy, cloud policy and interoperability framework; and (d) reconciles baselines, budgets, owners and dates. References in this Strategy shall identify the title, version, approval date and status of the policy instrument relied upon.
    HLTF-03. Make the methodology, country benchmarking and evidence base reproducible
    Strategy reference: §§1.6–1.7; sector ‘International alignment’ passages; Annex H
    Comment type: Policy / evidence / international relations
    Comment and implementation risk. The Strategy names a small set of countries as ‘pioneers’ and states that selected national strategies informed the work, but gives no selection criteria, comparator groups, variables, time periods, performance evidence or transferability test. Comparative learning is valuable; selective endorsement without a method may imply an official ranking, overlook relevant Member States and create unnecessary reputational or competitive signalling. The listed meetings likewise do not amount to a published stakeholder map, evidence register or impact assessment.
    Requested amendment. Replace country praise with a neutral benchmarking method and publish the evidence, assumptions, limitations and consultation-response report.
    Proposed text for insertion or replacement
    Comparative and consultation methodology. International examples shall be used as evidence sources, not as country rankings or general endorsements. A benchmarking annex shall identify the policy question, transparent selection criteria, peer group, indicators, data year, source quality, implementation outcomes, Cyprus transferability constraints and limitations for each comparator. The final Strategy shall include an evidence register, stakeholder-category map, summary of options considered, principal assumptions, distributional and fundamental-rights impacts, and a reasoned consultation report explaining which material comments were accepted, partly accepted or rejected. Country references unsupported by that method shall be removed or expressed neutrally.
    HLTF-04. Conform the Strategy to the 2026 draft AI implementing law and the final enacted framework
    Strategy reference: §3.3.1; §3.9.6; §§3.13–4.3; Annexes A–C
    Comment type: Legal / institutional sequencing
    Comment and implementation risk. The proposed national law for implementing Regulation (EU) 2024/1689 was published for consultation on 16 August 2026, during the Strategy consultation. It allocates functions to the Commissioner of Electronic Communications, the Commissioner for Personal Data Protection, the Central Bank and any further designated authority; identifies the national accreditation function; and provides a national regulatory-sandbox mechanism. The Strategy instead creates or names bodies with overlapping regulatory, audit, registry, certification and sandbox functions. The two instruments cannot safely proceed on parallel, inconsistent institutional assumptions.
    Requested amendment. Require a formal concordance after the Bill is finalised, preserve the authority of the legislature and regulators, and distinguish policy coordination from statutory supervision.
    Proposed text for insertion or replacement
    Institutional concordance. Before the Strategy is submitted for final approval, and again following enactment of the national law implementing Regulation (EU) 2024/1689, the Attorney-General’s Office and the responsible Deputy Ministry shall complete and publish an article-by-article concordance table. It shall map every Strategy body and function to the competent authority, legal basis, accountability route, appeal or complaint mechanism, information-sharing power and funding source. Strategy bodies may coordinate policy and delivery but shall not exercise market-surveillance, notifying-authority, accreditation, certification, enforcement, complaints, sanctioning or regulatory-sandbox powers unless those powers are expressly conferred by applicable law. Any inconsistent Strategy wording shall be amended automatically through a published conformance update.
    HLTF-05. Clarify governance, names, accountability and separation of functions
    Strategy reference: §§3.3.1–3.3.2; glossary; Annex B
    Comment type: Governance / administrative law
    Comment and implementation risk. The governance architecture uses inconsistent names and roles, including ‘Council’ and ‘Committee’, and describes the Taskforce both as independent advisory body and central coordinating body. The National AI Authority is simultaneously presented as policy coordinator, executor and control gatekeeper. Other entities prototype, validate, procure, approve, monitor or certify. Without a single responsibility matrix, the same institution may sponsor a system and assure it, weakening independence and creating conflicts.
    Requested amendment. Publish a definitive governance schedule and apply separation of policy, delivery, assurance and enforcement.
    Proposed text for insertion or replacement
    Governance and separation of functions. Annex A shall contain the definitive name, legal form, mandate, membership, appointment process, term, conflicts policy, decision rights, reporting line, budget and review date for every Strategy body. A RACI matrix shall cover policy, funding, procurement, data access, development, deployment approval, conformity assessment, audit, incident response, market surveillance and redress. No body that develops, funds, procures or operates an AI system shall provide the final independent assurance or statutory enforcement decision for that same system. Duplicate names and inconsistent glossary definitions shall be corrected. Existing constitutional, ministerial, regulatory, judicial and independent-authority competences remain unaffected.
    HLTF-06. Recognise CYS and preserve the national quality-infrastructure boundaries
    Strategy reference: §§1.4.3–1.4.10, 2.5.1, 3.3.1, 3.12; §4.3; Annexes A, C and H
    Comment type: Legal / standards / institutional
    Comment and implementation risk. Formal standardisation is treated intermittently, CYS is not assigned a role, and ‘standards’ are sometimes described as outputs of the proposed National AI Authority. CYS is Cyprus’s official National Standardisation Body and exercises the national standardisation activity pursuant to Law 156(I)/2002, including national coordination and representation in CEN, CENELEC, ISO and IEC. Standardisation, accreditation, conformity assessment/certification, regulation and policy guidance are related but legally distinct functions.
    Requested amendment. Insert CYS into the governance and implementation architecture as standards coordinator, while expressly preserving the roles of regulators, the national accreditation body and conformity-assessment bodies.

    Proposed text for insertion or replacement
    National standardisation and quality infrastructure. CYS, as Cyprus’s official National Standardisation Body exercising the national standardisation activity pursuant to Law 156(I)/2002, shall coordinate national standards intelligence, national mirror-committee participation, adoption of European standards and access to international standards work relevant to this Strategy. The National AI Authority may issue policy frameworks, implementation guidance and common administrative controls, but shall not present those instruments as national, European, harmonised or international standards. Accreditation shall remain with the legally designated national accreditation body; certification and conformity assessment shall be performed only by competent bodies under applicable schemes; and statutory supervision shall remain with the competent authorities. A written cooperation protocol shall prevent overlap.

    HLTF-07. Correct the legal effect and technical description of standards
    Strategy reference: §§2.3.4, 3.11.2, 3.12.4, 3.13.1–3.13.3; Annex A; Annex H
    Comment type: Technical / legal accuracy
    Comment and implementation risk. The Strategy recommends ‘ISO 42001 as a standard for risk management’, treats ISO/IEC 27001 as if it were sufficient for AI security, and places the AIGP professional credential alongside standards. ISO/IEC 42001 is an AI management-system standard; ISO/IEC 23894 is dedicated AI risk-management guidance. A voluntary standard does not itself prove compliance with the AI Act. Under Article 40 of the AI Act, only an applicable harmonised standard or part cited in the Official Journal may confer the specified presumption of conformity.
    Requested amendment. Replace the current wording with a standards taxonomy and risk-based profile; correct Annex H.
    Proposed text for insertion or replacement
    Use and legal effect of standards. ISO/IEC 42001:2023 may support an organisational AI management system; ISO/IEC 23894:2023 may support AI risk management; ISO/IEC 42005:2025 may support AI system impact assessment; ISO/IEC 5338:2023 may support lifecycle processes; the ISO/IEC 5259 series may support data-quality governance; and ISO/IEC 27001:2022 and related controls may support information security. These references are voluntary unless law or contract makes them applicable. They do not replace legal analysis or automatically demonstrate AI Act conformity. Applicable European harmonised standards developed through CEN-CENELEC JTC 21 shall be monitored and used where appropriate after adoption and, for presumption of conformity, OJEU citation. Professional credentials shall be listed as training credentials, not standards.
    HLTF-08. Use the current AI Act and remove blanket registration and obsolete timing claims
    Strategy reference: §3.9.6; §§3.11–3.13; Annex A; sector roadmaps
    Comment type: EU law / compliance
    Comment and implementation risk. The Strategy includes readiness language tied to 2 August 2026, although consultation continues after that date, and says every organisation must register AI systems in the EU database ‘without exception’. Registration under the AI Act is role- and category-specific; it is not a universal registry duty. The legal timetable was also amended by Regulation (EU) 2026/1744, which entered into force on 27 July 2026. Static or inaccurate dates will make a 2032 strategy obsolete immediately.
    Requested amendment. Replace blanket claims with a maintained obligations register based on the AI Act as amended.
    Proposed text for insertion or replacement
    AI Act implementation register. All references to Regulation (EU) 2024/1689 shall mean that Regulation as amended, including Regulation (EU) 2026/1744, and any applicable delegated or implementing acts. The National AI Authority shall maintain, with the competent authorities, a dated public implementation register identifying obligations by role, system category and commencement date. Registration in the EU database or any national register shall be required only where applicable law requires it. The national implementation plan shall distinguish prohibited practices, transparency obligations, general-purpose AI obligations, Annex III high-risk systems, safety components of regulated products, public-authority deployer duties, fundamental-rights authorities and sector-specific law.
    HLTF-09. Redesign NAICF, audits and the proposed certification lab around lawful conformity routes
    Strategy reference: §3.9.6; Legal Services pillar; §4.3
    Comment type: Conformity assessment / legal / market access
    Comment and implementation risk. The text proposes annual audits by a ‘Cyprus AI Security & Certification Authority’, a central registry of systems ‘certified under EU rules’, pre-certification of high-risk and ‘foundation’ models, and international equivalence bridges. It does not identify the legal basis, applicable standard, scheme, accreditation, notified-body route, scope of certificate, surveillance, complaints, liability or recognition mechanism. The AI Act uses the term general-purpose AI model and prescribes conformity routes; policy branding cannot create EU recognition or equivalence.
    Requested amendment. Convert NAICF into optional readiness support unless and until a lawful scheme is established, and remove ‘pre-certification’, ‘dual recognition’ and blanket annual-audit claims.
    Proposed text for insertion or replacement
    National AI Compliance Framework. NAICF shall operate as a non-binding readiness, evidence and implementation-support framework unless a specific function is conferred by law. It shall not issue or imply regulatory approval, CE marking, presumption of conformity, notified-body status, accreditation, legal equivalence or safe harbour. Any audit or certification scheme shall identify its owner, normative requirements, competence criteria, accreditation basis, assessment route, scope, validity, surveillance, complaints, impartiality, liability and relationship to Articles 40–49 of the AI Act. The proposed laboratory may provide testing, evaluation and sandbox support; the terms ‘pre-certification’, ‘certified under EU rules’, ‘dual recognition’ and ‘foundation model’ shall be replaced by legally accurate descriptions.
    HLTF-10. Create an integrated fundamental-rights and public-law assurance gate
    Strategy reference: §§1.4.8, 2.5.5, 3.3.2, 3.9, 3.13; Annex B
    Comment type: Fundamental rights / administrative law
    Comment and implementation risk. The Strategy refers generally to ethics, fairness and mandatory legal assessments for high-impact systems but does not specify decision criteria, responsible officials, publication rules or interaction with the AI Act fundamental-rights impact assessment, GDPR data-protection impact assessment, equality, accessibility, children’s rights and administrative-law duties. ‘Ethics’ cannot replace legality, and a checklist cannot legitimise a use that lacks statutory competence or necessity.
    Requested amendment. Add one integrated, risk-based assessment and approval gate before procurement and deployment of high-impact public-sector AI.
    Proposed text for insertion or replacement
    Integrated rights and legality assessment. Before procurement, pilot or deployment of high-impact public-sector AI, the accountable public body shall document: legal competence and purpose; necessity and proportionality; AI Act classification and any required fundamental-rights impact assessment; GDPR lawful basis, Article 22 analysis and any required DPIA; equality and non-discrimination; accessibility; child and vulnerable-person safeguards; human decision authority; notice, reasons, review, complaint and remedy; security; evidential integrity; and less intrusive alternatives. The assessment shall be reviewed by the competent legal, data-protection, security and domain functions. A non-confidential summary and decision shall be published, subject only to lawful restrictions. Ethics review supplements and does not replace legal compliance.
    HLTF-11. Establish a lawful public-sector AI register, notice, human review and redress
    Strategy reference: §§3.3.2, 3.4, 3.9.6; Annexes B–C
    Comment type: Transparency / public law / rights
    Comment and implementation risk. The proposed ‘AI Registry’ is framed as cataloguing all market solutions, but no purpose, legal basis, scope, confidentiality rule or relationship with EU registration is defined. Citizens need transparency about State use, while businesses require protection of trade secrets and security information. Article 86 of the AI Act provides a limited right to explanation in specified circumstances; it should not be expanded or reduced by imprecise strategy language.
    Requested amendment. Create a public-sector register first, avoid duplicate filings, and define individual safeguards in legally accurate terms.

    Proposed text for insertion or replacement
    Public-sector AI transparency and redress. Cyprus shall maintain a public register of AI systems used by public bodies, linked where practicable to required EU registrations and avoiding duplicate filings. Each entry shall identify the accountable body, purpose, provider and material subcontractors, legal basis, AI Act classification, affected groups, data categories, human-oversight model, impact-assessment status, performance indicators, material incidents, procurement reference and complaint channel. Security-sensitive and protected commercial information may be withheld only on a documented legal basis. Affected persons shall receive meaningful notice and access to human review, reasons or explanation, complaint and judicial or administrative remedy to the extent provided by applicable law, without limiting stronger rights under other law. Non-digital service channels shall remain available for essential services.

    HLTF-12. Recast data as a governed resource rather than an unqualified national asset
    Strategy reference: §3.2; §3.7; sector data proposals; Annex A
    Comment type: Data law / governance / interoperability
    Comment and implementation risk. Calling data a ‘strategic national asset’ may be a useful policy metaphor but does not determine ownership, lawful access or reuse. The proposed lake, warehouse and hub model lacks a legal classification of personal, non-personal, confidential, open, sectoral and protected data; a controller/processor map; purpose and access rules; retention; provenance; data-quality metrics; rights management; and a decision between centralised and federated architecture.
    Requested amendment. Insert a national AI data-governance framework aligned with the GDPR and the EU data acquis, and require data-product documentation.
    Proposed text for insertion or replacement
    Data governance for AI. Data shall be treated as a governed public-interest resource where law permits, not as property of the State by default. Before access or reuse, each dataset shall have a named steward; legal and rights classification; controller/processor or other role allocation; purpose and lawful basis; provenance; quality and representativeness measures; access conditions; licensing and intellectual-property status; retention and deletion rule; security classification; data-subject or third-party rights process; and audit record. Architecture shall favour federated access, minimisation and purpose limitation where centralisation is unnecessary. The framework shall align, as applicable, with the GDPR, Data Governance Act, Data Act, Open Data Directive, EHDS, trade-secret and copyright law, sector confidentiality and the European Interoperability Framework, supported by the ISO/IEC 5259 series and relevant European standards.
    HLTF-13. Make public procurement the principal implementation control
    Strategy reference: §§3.3.2, 3.4.1, 4.1; first six transformational procurements; Annex B
    Comment type: Public procurement / contracts / implementation
    Comment and implementation risk. The Strategy proposes six transformational procurements within eight months and an ‘AI-first’ procurement direction, but does not supply minimum readiness gates or contract terms. Buying quickly before requirements, data rights, interfaces, evidence and exit are defined can lock the State into providers and shift compliance risk to taxpayers. ‘AI-first’ may also bias problem definition toward technology instead of public value and proportionality.
    Requested amendment. Replace ‘AI-first’ with problem-led, outcome-based and rights-preserving procurement, and publish mandatory clauses before major tenders.
    Proposed text for insertion or replacement
    AI procurement standard. Public bodies shall procure AI only where a documented problem, lawful purpose and proportionate business case show that AI is suitable compared with non-AI alternatives. Before tender, the body shall complete classification, data-readiness, rights, security, accessibility, competition and exit assessments. Mandatory contract schedules shall address: provider/deployer roles; model and material-subcontractor transparency; data, input and output rights; training and improvement use; logging and evidence retention; performance and bias testing; human oversight; cybersecurity; incident and regulator cooperation; material model-change control; audit access; service levels; intellectual property; confidentiality; product and professional liability; insurance; portability, open formats, interfaces and exit assistance; deletion/return of data; sustainability metrics; and termination. No transformational procurement shall launch until these templates and an independent assurance route are approved.
    HLTF-14. Unify regulatory sandboxes, testbeds and innovation facilities
    Strategy reference: §§3.4–3.9; LegalTech and sector sandboxes; §4.3
    Comment type: Regulatory governance / innovation
    Comment and implementation risk. The Strategy repeatedly proposes sector sandboxes and testing facilities without distinguishing a statutory AI regulatory sandbox from experimentation, testbeds, accelerators, centres of excellence and conformity assessment. The draft implementing Bill assigns the national regulatory sandbox to the identified competent authorities. Multiplying ‘sandboxes’ without a common legal gateway risks regulatory arbitrage, duplicated applications and false impressions of approval.
    Requested amendment. Create one national sandbox framework with sector pathways and common entry, exit and publication rules.
    Proposed text for insertion or replacement
    Sandbox and testing architecture. The national AI regulatory sandbox shall be operated only by the authority or authorities designated by law and in accordance with the AI Act. Sector regulators, the Data Protection Commissioner, CYS, accreditation and conformity-assessment actors, research facilities and domain experts shall participate within their respective competences. Innovation hubs, accelerators and testbeds may provide technical experimentation but shall not imply regulatory approval. A single public framework shall define eligibility, SME and startup support, application criteria, real-world testing conditions, data protection, intellectual property, confidentiality, liability, incident response, standards participation, regulator coordination, duration, exit report, evidential value and the express statement that participation does not remove legal obligations.
    HLTF-15. Treat the National AI Infrastructure as a regulated critical dependency
    Strategy reference: §§3.7.1–3.7.4 and 3.13.2–3.13.3; Annex A
    Comment type: Cybersecurity / resilience / critical infrastructure
    Comment and implementation risk. The Strategy describes the National AI Infrastructure as critical national infrastructure but does not map designation, competent authorities or duties under NIS2, the CER Directive, the Cybersecurity Act, the Cyber Resilience Act or sector rules. Generic ‘national cybersecurity frameworks’ are insufficient for shared compute, model access, sensitive data, cross-border cloud, supply-chain threats and systemic concentration.
    Requested amendment. Require a criticality and regulatory assessment before architecture or procurement, plus measurable resilience and recovery controls.
    Proposed text for insertion or replacement
    Critical AI infrastructure assurance. Before design approval, the responsible authority shall determine and publish the legal classification, essential/important-entity status, critical-entity dependencies and competent supervisory arrangements for each infrastructure component under NIS2, the CER Directive, applicable Cyprus law, the EU Cybersecurity Act, the Cyber Resilience Act and sector regimes. Architecture and procurement shall include zero-trust access, tenant isolation, secure development, model and data supply-chain controls, vulnerability handling, cryptographic agility, adversarial testing, logging, forensic readiness, continuity, geographic and provider concentration limits, tested recovery objectives, portability and exit, incident-reporting interfaces and independent security evaluation. ENISA guidance and applicable standards shall be tracked in a maintained control profile.
    HLTF-16. Define digital sovereignty through measurable control, competition and exit
    Strategy reference: §3.7.3; public-sector platforms; Annex C
    Comment type: Competition / cloud / strategic autonomy
    Comment and implementation risk. ‘Digital sovereignty’ is defined at a high level and then associated with specific infrastructure choices. Sovereignty is not achieved merely through local hosting, ownership or a favoured hardware architecture. A system may be physically local yet operationally dependent on a foreign hyperscaler, proprietary model, unavailable weights, non-portable data or a single integrator. Conversely, carefully governed European or cross-border services may increase resilience.
    Requested amendment. Adopt outcome-based sovereignty criteria and technology-neutral procurement.
    Proposed text for insertion or replacement
    Digital sovereignty and contestability. Sovereignty shall be measured by lawful control over data and keys; ability to audit and govern models; continuity under supplier failure or geopolitical disruption; portability of data, prompts, logs, configurations and workloads; open and documented interfaces; substitutability of critical components; availability of skills and maintenance; compliance with EU law; and tested exit within defined time and cost. Procurement shall be technology-neutral and shall not prescribe a processor, model or distributed architecture without a published proportionality, security, competition and lifecycle-cost assessment. Multi-cloud or sovereign-cloud claims shall be evidenced, and material provider/model concentration shall be reported annually.
    HLTF-17. Add a technology-convergence and distributed-systems strategy
    Strategy reference: §§1.3–1.4, 2.3.4, 3.7, 3.12; sector roadmaps
    Comment type: Emerging technology / standards / strategic
    Comment and implementation risk. The Strategy largely treats AI as a standalone technology even though implementation will depend on cloud-edge/HPC, IoT, robotics, digital twins, digital identity and trust services, cybersecurity, smart contracts, tokenisation and blockchain/DLT. The absence is especially striking where the text already proposes a blockchain registry. Convergence affects architecture, evidence, security, liability, interoperability and skills; it should not be addressed through isolated use cases.
    Requested amendment. Insert a horizontal, technology-neutral convergence section with a use-case test and coordinated standards participation.
    Proposed text for insertion or replacement
    Converging technology systems. Cyprus shall govern AI as part of distributed socio-technical systems that may combine cloud and edge computing, high-performance computing, IoT, digital twins, robotics and autonomous systems, digital identity and trust services, cybersecurity, smart contracts, tokenisation and blockchain/DLT. Each proposed combination shall pass a documented use-case test covering necessity, comparative architecture, legal roles, data flows, security, interoperability, environmental cost, governance, evidence and exit. DLT shall be used only where distributed control, tamper-evidence or shared state provides demonstrable value over a conventional database. CYS shall coordinate relevant participation across ISO/IEC JTC 1/SC 42, ISO/TC 307, CEN-CENELEC JTC 21, CEN/CLC JTC 19, ETSI and sector committees so that common system descriptions and interfaces can be developed without displacing committee competence.
    HLTF-18. Correct AIREG: DLT records can support evidence, not manufacture ownership
    Strategy reference: Legal Services pillar, pp. 74–76; AIREG
    Comment type: Intellectual property / evidence / DLT
    Comment and implementation risk. AIREG is said to provide ‘immutable certification’ and a strong presumption of ownership across the EU. A ledger entry can help prove that a particular hash or assertion existed at a time and has not been altered. It does not establish authorship, originality, title, lawful training, absence of infringement or the truth of the recorded claim, and a Cyprus strategy cannot create an EU-wide ownership presumption. Immutability also conflicts with rectification, revocation, key compromise and data-protection requirements if designed poorly.
    Requested amendment. Recast AIREG as a feasibility study for a rights-evidence and provenance service aligned with eIDAS and IP law.
    Proposed text for insertion or replacement
    AI provenance and rights-evidence feasibility study. The proposed AIREG shall not be described as certifying ownership or creating a legal presumption across the Union. A feasibility study shall compare conventional and DLT architectures and assess legal basis, governance, evidential effect, identity assurance, time-stamping, qualified electronic ledgers and archiving under eIDAS as amended, WIPO and EU intellectual-property rules, GDPR, trade secrets, cybersecurity, interoperability, correction and revocation, key loss, dispute resolution, liability and long-term preservation. Any pilot may record signed claims, hashes, provenance events and licences, but shall state that technical integrity does not prove the truth, lawfulness, authorship or ownership of the underlying asset. Legal effect shall arise only from applicable law and admissible evidence.
    HLTF-19. Remove the ‘AI Judge’ commitment pending constitutional and justice-system reform
    Strategy reference: Legal Services pillar, pp. 74–76; Annex C
    Comment type: Constitutional / judicial / fundamental rights
    Comment and implementation risk. The proposal for an ‘AI judge’ in low-value, factually uncontested cases is not a mere digital-service project. It concerns the exercise of judicial power, independence and impartiality, Article 30 of the Constitution, Article 47 of the EU Charter, Article 6 ECHR, procedural law, open justice, evidence, reasons, appeal and equality of arms. Monetary value and absence of a factual dispute do not remove questions of law or vulnerability. AI used to prepare judicial decisions is also a high-risk category under the AI Act.
    Requested amendment. Delete the commitment to an AI judge. Permit carefully governed administrative and judicial support only, unless future primary law and constitutional analysis authorise more.
    Proposed text for insertion or replacement
    Justice-sector AI. The term and proposal ‘AI Judge Capability’ shall be deleted. AI may be evaluated for transcription, translation, scheduling, search, document triage, legal research and non-binding decision support, subject to judicial governance, procurement, security, evidence, data protection, professional secrecy, accessibility and fundamental-rights safeguards. A natural judge or legally authorised decision-maker shall retain responsibility for the decision, factual and legal assessment, reasons and remedy. Any future proposal for automated adjudication shall require a separate public justice strategy, constitutional and human-rights opinion, primary legal basis, judicial and Bar consultation, equality and accessibility assessment, pilot evaluation, public transparency and an effective right to human determination and appeal.
    HLTF-20. Govern court transcription and a Cyprus case-law model as justice infrastructure
    Strategy reference: Legal Services pillar, pp. 74–76
    Comment type: Justice / data / evidence / procurement
    Comment and implementation risk. AI transcription and a case-law language model can improve access, but the current text does not address authoritative records, correction, speaker identification, protected hearings, anonymisation, hallucinations, source citation, copyright/database rights, judicial independence, professional secrecy or whether citizens may rely on outputs. A model trained on incomplete or non-authoritative judgments may entrench error.
    Requested amendment. Add a justice-data governance and staged evaluation programme; never label model output as authoritative legal advice or an official judgment.
    Proposed text for insertion or replacement
    Court records and case-law AI. The Supreme Court and competent justice authorities shall own governance of any transcription or case-law AI service. A pilot shall define the authoritative record, human verification, correction procedure, source provenance, citation to the controlling judgment, coverage limitations, protected-hearing controls, anonymisation, retention, access tiers, cybersecurity, professional secrecy, copyright and database rights, model evaluation and incident response. Public outputs shall disclose that they are generated or assisted by AI and are not the authoritative judgment or legal advice. No system shall train on confidential material or use court data for provider model improvement without express legal and contractual authority. Independent accuracy, language and equality testing shall precede scale-up.
    HLTF-21. Limit the Digital AML Certification Scheme to interoperable evidence exchange
    Strategy reference: Legal Services pillar, pp. 74–76; Financial Services pillar
    Comment type: AML / financial regulation / liability
    Comment and implementation risk. The proposed certificate would ‘enable reliance’ by obliged entities and authorities. Under EU and national AML rules, reliance, outsourcing and information exchange do not automatically transfer each obliged entity’s responsibility for customer due diligence, risk assessment, monitoring, sanctions controls and suspicious-activity reporting. A certificate may become stale, be wrong, reveal sensitive data or create systemic reliance on one provider.
    Requested amendment. Reframe the initiative as a regulated, revocable and purpose-limited evidence exchange; do not promise discharge from AML duties.
    Proposed text for insertion or replacement
    Digital AML evidence exchange. Any Digital AML Certification Scheme shall be developed with the competent AML supervisors, Data Protection Commissioner and obliged-sector representatives, and aligned with the applicable EU AML package, GDPR, eIDAS, DORA and sector secrecy. It may support interoperable, verifiable and time-bounded exchange of specified due-diligence evidence, but shall not state or imply that an obliged entity is discharged from its own legal duties. The scheme shall define issuer competence, assurance level, data minimisation, consent or other legal basis, permitted reliance, freshness, revocation, sanctions and PEP updates, correction, audit, liability allocation, regulator access, cross-border transfer, cyber incident handling and alternatives for persons unable to use the service.
    HLTF-22. Add a complete intellectual-property, trade-secret and AI value-chain framework
    Strategy reference: §§3.2, 3.5, 3.11; Legal Services pillar; Annex A
    Comment type: IP / commercial law / GPAI
    Comment and implementation risk. The Strategy proposes clarifying protection for ‘computer-generated works’ but does not address the full value chain: training-data acquisition and text-and-data-mining reservations; rights in datasets, models, prompts and outputs; open-source licences; employee/contractor ownership; confidential information; model-provider terms; GPAI copyright duties; provenance; infringement allocation and remedies. Creating a bespoke national right without EU-compatibility analysis could fragment the internal market or produce false confidence.
    Requested amendment. Replace the narrow promise with an expert review and standard contractual toolkit aligned with EU law.
    Proposed text for insertion or replacement
    AI intellectual-property and value-chain framework. Cyprus shall undertake an evidence-based review of copyright, database rights, trade secrets, patents, open-source licensing, contractual rights and GPAI obligations across data acquisition, training, fine-tuning, retrieval, deployment and output use. The review shall assess EU competence and harmonisation limits before proposing national legislation. Public procurement and SME support shall include model clauses on authorised data use, text-and-data-mining reservations, provenance, confidential inputs, provider training use, model and output licences, open-source obligations, infringement warranties, notice-and-takedown, indemnities, audit evidence and termination. No registry entry or contractual label shall be presented as creating ownership that applicable law does not recognise.
    HLTF-23. Build a proportionate startup and SME compliance-to-scale pathway
    Strategy reference: §§2.5.4, 3.5, 4.2–4.3; NAICF Comply and AdoptNAICF
    Comment type: Startups / SMEs / investment / State aid
    Comment and implementation risk. The Strategy rightly prioritises adoption and funding, but certification-heavy or one-size-fits-all requirements may price startups out before product-market fit. Conversely, grants without legal, procurement and evidence readiness can fund pilots that never scale. National-residency preferences may also conflict with EU procurement, establishment and State-aid rules. Support must follow role, risk and maturity.
    Requested amendment. Create staged support from classification to cross-border scale, using lawful access criteria and reusable evidence.
    Proposed text for insertion or replacement
    Startup and SME implementation pathway. Cyprus shall provide a proportionate, risk-based pathway comprising: free classification and regulatory clinics; AI literacy and standards navigation; model contract and DPIA/FRIA templates; compute and test-data vouchers; access to the statutory sandbox and testing facilities; security and red-team support; procurement-readiness coaching; staged grants tied to evidence and milestones; and support for CE-marking or conformity routes where legally applicable. Requirements shall scale by role, system risk and maturity. Public procurement shall use proportionate turnover, insurance and prior-experience criteria, suitable lotting and transparent challenge-based procedures, without unlawful nationality or residence discrimination. Funding shall address State-aid rules, intellectual property, follow-on finance, commercialisation and measurable additionality.
    HLTF-24. Add liability, insurance, incident and forensic-evidence architecture
    Strategy reference: §§3.3.2, 3.9, 3.13; Annexes B–C
    Comment type: Liability / evidence / enforcement
    Comment and implementation risk. The Strategy focuses on controls but not on who bears loss when AI fails. Software and AI are addressed by the revised EU Product Liability Directive, while contract, tort, professional duties, public-law liability and sector rules continue to apply. Dynamic models also require evidence that can reconstruct versions, inputs, outputs, human interventions and post-deployment changes. Ordinary logs may be incomplete or controlled by the supplier.
    Requested amendment. Add a liability and evidence workstream before procurement, not after an incident.
    Proposed text for insertion or replacement
    Liability, insurance and forensic readiness. Every high-impact AI initiative shall maintain a responsibility and liability map covering provider, deployer, importer, distributor, integrator, data supplier, cloud/model provider, professional user and public authority. Procurement shall address the revised Product Liability Directive, applicable contract, tort, professional, public-law and sector liability; evidence disclosure; warranties; indemnities; caps; insurance; limitation periods; and recourse through the supply chain. Systems shall preserve proportionate, secure and admissible evidence of model/version, configuration, data provenance, inputs and outputs, human review, changes, incidents and remediation, with retention and access rules. Cyprus shall support CYS-coordinated participation in relevant AI, DLT and digital-evidence standardisation, including international forensic-evidence work, without predetermining its outcome.
    HLTF-25. Make sustainability and island-resource constraints binding investment gates
    Strategy reference: §§3.7.1–3.7.4, 3.13; Annexes C and F
    Comment type: Sustainability / infrastructure / investment
    Comment and implementation risk. Compute ambitions are not tied to an energy, water, land, grid, carbon or hardware-lifecycle baseline. For an island system, data-centre and AI-factory decisions can create material grid and water dependencies, stranded assets and exposure to imported equipment. Generic references to sustainable infrastructure are not enough for investment appraisal.
    Requested amendment. Require resource and climate gates for all publicly funded compute and major cloud procurements.
    Proposed text for insertion or replacement
    Sustainable AI infrastructure. No major public AI compute or data-centre investment shall proceed without a published whole-life assessment of demand, utilisation, alternatives and shared European capacity; grid connection and resilience; energy source and additionality; water availability and WUE; PUE; embodied carbon and equipment lifecycle; heat reuse; land and permitting; supply-chain concentration; climate adaptation; decommissioning; and total public cost. Tenders shall include comparable metrics, metering, reporting, efficiency thresholds and improvement obligations. The National AI Infrastructure Council shall publish annual capacity, utilisation, energy, water, carbon, outage and cost indicators and explain whether local build, federated access or European shared capacity offers the best public value.
    HLTF-26. Add labour, professional-responsibility, education and accessibility safeguards
    Strategy reference: §§3.4–3.6; Education and Human Capital pillar; Annex C
    Comment type: Employment / education / inclusion
    Comment and implementation risk. The Strategy promotes augmentation and reskilling but does not provide workforce-impact assessment, worker consultation, protections for algorithmic management, professional accountability, academic integrity or equitable access. AI literacy is a legal obligation in the AI Act but cannot be reduced to tool training. Children, persons with disabilities, non-digital users and workers affected by monitoring or task redesign require specific safeguards.
    Requested amendment. Insert a social and professional transition framework with accessibility by design.
    Proposed text for insertion or replacement
    Human capability and just transition. Public bodies and publicly funded projects shall assess workforce, professional-responsibility, equality, accessibility and skills impacts before deployment. Employers shall provide role-based AI literacy, consult workers and representatives where required, and retain accountable human professional judgement in regulated services. Education uses shall address child rights, teacher control, academic integrity, assessment validity and age-appropriate data protection. Digital services shall meet applicable accessibility requirements and maintain reasonable non-digital alternatives for essential services. The National AI Skills Observatory shall publish disaggregated outcomes, job-quality effects and skills gaps, while training credentials shall be quality-assured and clearly distinguished from standards, licences and regulatory certifications.

    HLTF-27. Create sector legal maps before sector deployment
    Strategy reference: Priority-sector roadmaps and Annex C
    Comment type: Sector regulation / implementation
    Comment and implementation risk. The Strategy’s sector roadmaps often state ‘full alignment’ with EU law without identifying the actual regulatory perimeter, competent regulator, professional decision-maker, evidence standard or additional sector approval. The result is greatest in health, finance, education, employment, maritime, critical infrastructure, justice, law enforcement and public benefits, where AI Act duties coexist with product, safety, data, consumer and professional rules.
    Requested amendment. Make a sector legal and standards map a condition to funding and procurement.
    Proposed text for insertion or replacement
    Sector implementation dossiers. Before funding or procurement in a priority sector, the responsible ministry and competent regulators shall publish a dossier identifying: intended use and AI Act classification; provider/deployer and product-supply-chain roles; applicable sector and professional law; competent authorities; data-access and confidentiality rules; required authorisations and conformity route; fundamental-rights and safety assessment; standards profile; clinical, financial, educational, judicial or operational evidence; human decision authority; incident and complaint routes; liability and insurance; and post-deployment monitoring. At minimum, the dossiers shall address health and medical-device law and EHDS; DORA, MiCA, the DLT Pilot Regime and AML law for finance; education, employment and platform-work law; maritime and product-safety rules; and justice, law-enforcement and biometric safeguards.
    HLTF-28. Replace aspirational KPIs with baselines, owners, budgets and independent evaluation
    Strategy reference: §§1.5, 2.4, 4.4; Annex F; sector targets
    Comment type: Delivery / public finance / evaluation
    Comment and implementation risk. Headline targets – including GDP uplift, productivity, 75% adoption and three unicorns – are not accompanied by definitions, baselines, causal models, costs, sensitivity analysis or accountable owners. Adoption is not consistently dated (2030 and 2032). Annex F is described as indicative and may be changed without revising the core Strategy, weakening accountability. Counting deployments can reward low-value or risky use.
    Requested amendment. Publish a costed delivery portfolio and independent evaluation protocol before commitments are treated as targets.

    Proposed text for insertion or replacement
    Delivery, finance and evaluation. Within 120 days, each programme shall have an accountable senior owner, delivery partner, legal basis, baseline, target definition, population, data source, methodology, milestones, dependencies, budget and funding source, procurement route, risk appetite, benefits-realisation plan and stop/scale criteria. Targets shall distinguish adoption from effective, lawful and sustained use. The 75% target and its year shall be reconciled across the document. Macroeconomic and productivity claims shall disclose the model, assumptions, confidence range and attribution limits. An independent evaluator shall publish annual results, incidents, distributional impacts, cost variance and reasons for continuation, modification or termination. Material KPI changes shall require a dated public change notice and governance approval.

  5. Commentary on the Cyprus National AI Strategy 2032
    Building an Operational Sovereign AI Ecosystem for Cyprus and Europe
    Submitted by Shadgunya Technologies Group
    Shadgunya Technologies welcomes the Cyprus National AI Strategy 2032 and strongly supports its ambition to establish Cyprus as a trusted AI hub in the Eastern Mediterranean and a reliable European jurisdiction for AI-enabled services.
    The Strategy correctly recognises that AI sovereignty does not require technological isolation. It requires Cyprus to retain meaningful control over critical compute infrastructure, strategic data, models, operational governance, security and skills, while using trusted European and international partnerships to achieve scale. Its proposals for a National AI Infrastructure, federated data architecture, sovereign specialised language models, the Government Innovation Hub, Pharos-CY integration and European AI assurance capabilities provide a strong foundation.
    The next step should be to translate these principles into an enforceable national architecture, procurement framework and funded implementation programme.
    1. Define AI sovereignty as measurable control
    The Strategy should include an operational definition of sovereignty covering six layers:
    1. Data sovereignty: Cyprus retains control over the location, access, classification, reuse, retention and deletion of national data.
    2. Compute sovereignty: Sensitive workloads can be operated within infrastructure controlled by Cyprus, including protected on-island and offline environments.
    3. Model sovereignty: Cyprus can inspect, evaluate, fine-tune, replace and independently operate the models used for critical public functions.
    4. Operational sovereignty: Government systems can continue functioning during loss of external connectivity, geopolitical disruption, vendor failure or suspension of a commercial service.
    5. Security and supply-chain sovereignty: Cyprus retains encryption-key custody, complete auditability and visibility into software, model and hardware dependencies.
    6. Economic and intellectual-property sovereignty: Public investment creates local skills, Cypriot employment, locally anchored IP and exportable European products.
    Every critical AI procurement should be assessed against these six dimensions. Any exception should require documented approval from the National AI Authority.
    2. Establish a tiered National Sovereign AI Infrastructure
    The proposed National AI Infrastructure should not be treated as a single data centre or GPU cluster. It should be a distributed national capability with three security zones:
    ● European and commercial compute: For non-sensitive research, general experimentation and large-scale training.
    ● Cyprus Government AI Cloud: For regulated public-sector workloads, operated under Cypriot governance and integrated with the G-Cloud.
    ● Protected sovereign environments: On-island, offline, air-gapped or edge infrastructure for defence, law enforcement, healthcare, critical infrastructure and other highly sensitive applications.
    Large-scale training may use EuroHPC and European AI Factories, while sensitive data processing and mission-critical inference remain under Cypriot control. This would implement the Strategy’s intended balance between sovereign capability and European integration
    The infrastructure roadmap should specify:
    ● Initial and projected GPU capacity.
    ● Guaranteed compute allocation for government, universities and startups.
    ● Two-site resilience and disaster recovery.
    ● Encryption-key custody and privileged-access controls.
    ● Minimum availability and recovery targets.
    ● Energy source, cooling, water consumption and power-usage efficiency.
    ● GPU utilisation, waiting time and cost per workload.
    ● Hardware and software renewal cycles.
    ● Procedures for disconnected and degraded operations.
    A minimum viable sovereign infrastructure should become operational before 2028, followed by modular expansion through 2032.
    3. Correct the sequencing between architecture and procurement
    The Strategy proposes launching procurements for six transformational AI solutions within eight months. This creates a risk that applications will be purchased before national standards for data, models, APIs, security and portability have been established.
    During the first 180 days, Cyprus should complete:
    ● A National Sovereign AI Reference Architecture.
    ● Government-wide data classification and AI workload classification.
    ● Common API, identity, logging and model-interface standards.
    ● Standard contractual clauses for AI procurement.
    ● A national model and application registry.
    ● Minimum security, testing and lifecycle requirements.
    ● Vendor exit, data portability and continuity procedures.
    Critical AI contracts should require open interfaces, exportable data, reproducible deployment, source-code or model-artifact escrow where appropriate, software and model bills of materials, independent security testing, local knowledge transfer and clearly defined government rights over improvements developed using public data.
    This would prevent foreign platform dependence from becoming embedded through early procurements.
    4. Build a federated national data fabric—not merely a central warehouse
    The Strategy appropriately calls for federated data architecture and sectoral data spaces. This should be expanded into an operational National Data Fabric containing:
    ● A catalogue of national and sectoral datasets.
    ● Standard metadata and semantic definitions.
    ● Data lineage, provenance and quality scoring.
    ● Purpose-based access and consent controls.
    ● Privacy-preserving research environments and data clean rooms.
    ● Federated query and analytics capabilities.
    ● APIs for authorised government and industry use.
    ● Immutable audit trails for sensitive access.
    ● Synthetic and anonymised datasets for innovation.
    Cyprus should also create trusted national language and knowledge resources covering Cyprus-relevant legal, administrative, financial, maritime, tourism and public-service terminology. These resources can support specialised multilingual models without requiring Cyprus to train a very large general-purpose model from the beginning.
    5. Prioritise specialised sovereign models and reusable components
    Cyprus does not need to compete by building the largest foundation model. It can differentiate by developing smaller, efficient and auditable models for regulated European use.
    A National AI Model Gateway should allow ministries to use multiple European, open-weight and commercial models through a common governed interface. It should support:
    ● Specialised language models for Cypriot law and public administration.
    ● Retrieval from authoritative government sources.
    ● Multilingual document and speech intelligence.
    ● Model routing based on security, cost and accuracy.
    ● Central evaluation and approval.
    ● On-premise and edge inference.
    ● Model replacement without rewriting applications.
    ● Continuous monitoring for accuracy, bias, hallucination and data leakage.
    Common capabilities such as document intelligence, identity resolution, multilingual assistants, entity correlation, geospatial analytics and case management should be built once and reused across ministries, consistent with the Strategy’s own “build once, reuse everywhere” principle.
    6. Make AI security and assurance a continuous operational function
    Compliance should not stop at certification. Cyprus should establish continuous AI assurance covering:
    ● Prompt-injection and data-exfiltration testing.
    ● Model poisoning and adversarial manipulation.
    ● Supply-chain and dependency assessment.
    ● Red-team testing before production.
    ● Runtime monitoring and anomaly detection.
    ● Human override and safe fallback.
    ● Version control, rollback and decommissioning.
    ● Incident reporting and coordinated response.
    ● Periodic re-evaluation after model or data changes.
    The proposed European AI Certification Lab should maintain appropriate organisational independence between system developers, operators and assessors. It can become an important European capability by combining EU AI Act readiness with practical cybersecurity and operational-resilience testing.
    7. Simplify governance and assign delivery accountability
    The Strategy proposes several authorities, councils, committees, observatories, hubs and Centres of Excellence. While each has value, overlapping responsibilities could slow execution.
    The National AI Authority should be the single accountable owner of:
    ● National architecture and technical standards.
    ● Common platforms.
    ● Compute allocation.
    ● Procurement templates.
    ● Portfolio prioritisation.
    ● Programme-level budgets.
    ● Quarterly delivery reporting.
    Specialised committees should provide oversight and expert advice without creating additional approval chains. Every flagship programme should have one accountable owner, a defined budget, a delivery timetable and measurable citizen or economic outcomes.
    Headline targets such as GDP expansion, the creation of three unicorns and the number of AI professionals should be supplemented with controllable operational indicators: production systems deployed, processing-time reduction, cost avoidance, locally owned IP, export revenue, compute utilisation, public trust, security incidents, SME participation and the percentage of critical workloads that can operate independently.
    8. Lessons from Shadgunya’s experience in India
    Through its group companies, Pinaca Technologies and Saptang Labs, Shadgunya has worked on sovereign AI, analytics, digital forensics and cybersecurity systems for sensitive government, law-enforcement, defence and national-security environments in India.
    Relevant completed and operational experience includes:
    ● Serving as a technology partner to MARVEL and supporting sensitive law-enforcement and intelligence requirements, including work associated with Maharashtra ATS.
    ● Providing digital-forensics capabilities to more than 15 Indian agencies, including Income Tax, Customs, the Enforcement Directorate, CBI and NIA.
    ● Delivering operational social-media monitoring services for India’s Ministry of Electronics and Information Technology.
    ● Supporting the Indian Cyber Crime Coordination Centre in money-mule and financial-investigation requirements.
    ● Deploying BlackFence remote-audit capabilities within Indian Army infrastructure.
    ● Delivering Sovereign AI Products through Indian Army and Indian Navy AI incubation ecosystems.
    ● Completing Soverign AI based engagements with BSNL and RailTel for network-scale cybersecurity capabilities.
    Our experience has produced five important observations:
    1. Government AI projects usually fail at the data and workflow layers, not at the model layer. Data preparation, system integration and operational adoption must therefore precede model selection.
    2. Sensitive systems require deployment flexibility. On-premise, offline, air-gapped, hybrid-cloud and edge deployment patterns must be part of the original architecture.
    3. Auditability is as important as accuracy. Investigative and regulatory systems require provenance, chain of custody, role-based access, human review and reproducible results.
    4. Shared capabilities create national scale. Document intelligence, entity correlation, language processing, geospatial analysis and case management should not be procured repeatedly by separate departments.
    5. Sovereignty ultimately depends on people. A system is not sovereign if local engineers cannot operate, secure, modify and recover it without continuous external dependence.
    9. Proposed Shadgunya contribution in Cyprus
    Shadgunya looks forward to adapting these field-tested engineering patterns to Cyprus under European legal, ethical and institutional requirements. We do not propose transferring Indian systems or operating models unchanged. The objective would be to co-develop Cyprus-owned, EU-aligned capabilities with local government, universities, research institutions and industry.
    Potential areas of collaboration include:
    ● Designing the National Sovereign AI Reference Architecture.
    ● Establishing a secure multi-model government AI platform.
    ● Developing specialised sovereign models for regulated sectors.
    ● Creating an AI cybersecurity, red-team and assurance environment.
    ● Supporting financial-crime, AML and fraud-intelligence applications.
    ● Building critical-infrastructure, maritime and national-resilience analytics.
    ● Developing offline and edge AI for sensitive government operations.
    ● Training Cypriot engineers, AI Officers and security professionals.
    ● Establishing joint R&D in RISC-V security, sovereign chiplets, SLMs and secure edge AI.
    ● Creating locally anchored IP and export-ready products from Cyprus.
    An initial programme could begin with three lighthouse implementations: a reusable government knowledge and document-intelligence platform, a regulated financial-crime and compliance platform, and an AI security and critical-infrastructure monitoring capability.
    Conclusion
    Cyprus has an opportunity to become more than a consumer of foreign AI services. It can become a European centre for the design, assurance and export of sovereign AI systems for governments and regulated industries.
    The Strategy provides the right direction. Its next iteration should define exactly what Cyprus must control, what it will build nationally, what it will access through Europe, and what every supplier must transfer to the Cypriot ecosystem.
    Shadgunya Technologies looks forward to establishing a Cyprus-based sovereign AI engineering, assurance and productisation capability. Our objective is to adapt experience gained from operational government, defence, investigative and cybersecurity projects in India; co-develop these capabilities within Cyprus; ensure alignment with European rights and regulatory frameworks; and use Cyprus as the base from which trusted sovereign AI products can be delivered across Europe.

  6. Commentary on the Cyprus National AI Strategy 2032
    Building an Operational Sovereign AI Ecosystem for Cyprus and Europe
    Submitted by Shadgunya Technologies Group
    Shadgunya Technologies welcomes the Cyprus National AI Strategy 2032 and strongly supports its ambition to establish Cyprus as a trusted AI hub in the Eastern Mediterranean and a reliable European jurisdiction for AI-enabled services.
    The Strategy correctly recognises that AI sovereignty does not require technological isolation. It requires Cyprus to retain meaningful control over critical compute infrastructure, strategic data, models, operational governance, security and skills, while using trusted European and international partnerships to achieve scale. Its proposals for a National AI Infrastructure, federated data architecture, sovereign specialised language models, the Government Innovation Hub, Pharos-CY integration and European AI assurance capabilities provide a strong foundation.
    The next step should be to translate these principles into an enforceable national architecture, procurement framework and funded implementation programme.
    1. Define AI sovereignty as measurable control
    The Strategy should include an operational definition of sovereignty covering six layers:
    1. Data sovereignty: Cyprus retains control over the location, access, classification, reuse, retention and deletion of national data.
    2. Compute sovereignty: Sensitive workloads can be operated within infrastructure controlled by Cyprus, including protected on-island and offline environments.
    3. Model sovereignty: Cyprus can inspect, evaluate, fine-tune, replace and independently operate the models used for critical public functions.
    4. Operational sovereignty: Government systems can continue functioning during loss of external connectivity, geopolitical disruption, vendor failure or suspension of a commercial service.
    5. Security and supply-chain sovereignty: Cyprus retains encryption-key custody, complete auditability and visibility into software, model and hardware dependencies.
    6. Economic and intellectual-property sovereignty: Public investment creates local skills, Cypriot employment, locally anchored IP and exportable European products.
    Every critical AI procurement should be assessed against these six dimensions. Any exception should require documented approval from the National AI Authority.
    2. Establish a tiered National Sovereign AI Infrastructure
    The proposed National AI Infrastructure should not be treated as a single data centre or GPU cluster. It should be a distributed national capability with three security zones:
    ● European and commercial compute: For non-sensitive research, general experimentation and large-scale training.
    ● Cyprus Government AI Cloud: For regulated public-sector workloads, operated under Cypriot governance and integrated with the G-Cloud.
    ● Protected sovereign environments: On-island, offline, air-gapped or edge infrastructure for defence, law enforcement, healthcare, critical infrastructure and other highly sensitive applications.
    Large-scale training may use EuroHPC and European AI Factories, while sensitive data processing and mission-critical inference remain under Cypriot control. This would implement the Strategy’s intended balance between sovereign capability and European integration
    The infrastructure roadmap should specify:
    ● Initial and projected GPU capacity.
    ● Guaranteed compute allocation for government, universities and startups.
    ● Two-site resilience and disaster recovery.
    ● Encryption-key custody and privileged-access controls.
    ● Minimum availability and recovery targets.
    ● Energy source, cooling, water consumption and power-usage efficiency.
    ● GPU utilisation, waiting time and cost per workload.
    ● Hardware and software renewal cycles.
    ● Procedures for disconnected and degraded operations.
    A minimum viable sovereign infrastructure should become operational before 2028, followed by modular expansion through 2032.
    3. Correct the sequencing between architecture and procurement
    The Strategy proposes launching procurements for six transformational AI solutions within eight months. This creates a risk that applications will be purchased before national standards for data, models, APIs, security and portability have been established.
    During the first 180 days, Cyprus should complete:
    ● A National Sovereign AI Reference Architecture.
    ● Government-wide data classification and AI workload classification.
    ● Common API, identity, logging and model-interface standards.
    ● Standard contractual clauses for AI procurement.
    ● A national model and application registry.
    ● Minimum security, testing and lifecycle requirements.
    ● Vendor exit, data portability and continuity procedures.
    Critical AI contracts should require open interfaces, exportable data, reproducible deployment, source-code or model-artifact escrow where appropriate, software and model bills of materials, independent security testing, local knowledge transfer and clearly defined government rights over improvements developed using public data.
    This would prevent foreign platform dependence from becoming embedded through early procurements.
    4. Build a federated national data fabric—not merely a central warehouse
    The Strategy appropriately calls for federated data architecture and sectoral data spaces. This should be expanded into an operational National Data Fabric containing:
    ● A catalogue of national and sectoral datasets.
    ● Standard metadata and semantic definitions.
    ● Data lineage, provenance and quality scoring.
    ● Purpose-based access and consent controls.
    ● Privacy-preserving research environments and data clean rooms.
    ● Federated query and analytics capabilities.
    ● APIs for authorised government and industry use.
    ● Immutable audit trails for sensitive access.
    ● Synthetic and anonymised datasets for innovation.
    Cyprus should also create trusted national language and knowledge resources covering Cyprus-relevant legal, administrative, financial, maritime, tourism and public-service terminology. These resources can support specialised multilingual models without requiring Cyprus to train a very large general-purpose model from the beginning.
    5. Prioritise specialised sovereign models and reusable components
    Cyprus does not need to compete by building the largest foundation model. It can differentiate by developing smaller, efficient and auditable models for regulated European use.
    A National AI Model Gateway should allow ministries to use multiple European, open-weight and commercial models through a common governed interface. It should support:
    ● Specialised language models for Cypriot law and public administration.
    ● Retrieval from authoritative government sources.
    ● Multilingual document and speech intelligence.
    ● Model routing based on security, cost and accuracy.
    ● Central evaluation and approval.
    ● On-premise and edge inference.
    ● Model replacement without rewriting applications.
    ● Continuous monitoring for accuracy, bias, hallucination and data leakage.
    Common capabilities such as document intelligence, identity resolution, multilingual assistants, entity correlation, geospatial analytics and case management should be built once and reused across ministries, consistent with the Strategy’s own “build once, reuse everywhere” principle.
    6. Make AI security and assurance a continuous operational function
    Compliance should not stop at certification. Cyprus should establish continuous AI assurance covering:
    ● Prompt-injection and data-exfiltration testing.
    ● Model poisoning and adversarial manipulation.
    ● Supply-chain and dependency assessment.
    ● Red-team testing before production.
    ● Runtime monitoring and anomaly detection.
    ● Human override and safe fallback.
    ● Version control, rollback and decommissioning.
    ● Incident reporting and coordinated response.
    ● Periodic re-evaluation after model or data changes.
    The proposed European AI Certification Lab should maintain appropriate organisational independence between system developers, operators and assessors. It can become an important European capability by combining EU AI Act readiness with practical cybersecurity and operational-resilience testing.
    7. Simplify governance and assign delivery accountability
    The Strategy proposes several authorities, councils, committees, observatories, hubs and Centres of Excellence. While each has value, overlapping responsibilities could slow execution.
    The National AI Authority should be the single accountable owner of:
    ● National architecture and technical standards.
    ● Common platforms.
    ● Compute allocation.
    ● Procurement templates.
    ● Portfolio prioritisation.
    ● Programme-level budgets.
    ● Quarterly delivery reporting.
    Specialised committees should provide oversight and expert advice without creating additional approval chains. Every flagship programme should have one accountable owner, a defined budget, a delivery timetable and measurable citizen or economic outcomes.
    Headline targets such as GDP expansion, the creation of three unicorns and the number of AI professionals should be supplemented with controllable operational indicators: production systems deployed, processing-time reduction, cost avoidance, locally owned IP, export revenue, compute utilisation, public trust, security incidents, SME participation and the percentage of critical workloads that can operate independently.
    8. Lessons from Shadgunya’s experience in India
    Through its group companies, Pinaca Technologies and Saptang Labs, Shadgunya has worked on sovereign AI, analytics, digital forensics and cybersecurity systems for sensitive government, law-enforcement, defence and national-security environments in India.
    Relevant completed and operational experience includes:
    ● Serving as a technology partner to MARVEL and supporting sensitive law-enforcement and intelligence requirements, including work associated with Maharashtra ATS.
    ● Providing digital-forensics capabilities to more than 15 Indian agencies, including Income Tax, Customs, the Enforcement Directorate, CBI and NIA.
    ● Delivering operational social-media monitoring services for India’s Ministry of Electronics and Information Technology.
    ● Supporting the Indian Cyber Crime Coordination Centre in money-mule and financial-investigation requirements.
    ● Deploying BlackFence remote-audit capabilities within Indian Army infrastructure.
    ● Delivering Sovereign AI Products through Indian Army and Indian Navy AI incubation ecosystems.
    ● Completing Soverign AI based engagements with BSNL and RailTel for network-scale cybersecurity capabilities.
    Our experience has produced five important observations:
    1. Government AI projects usually fail at the data and workflow layers, not at the model layer. Data preparation, system integration and operational adoption must therefore precede model selection.
    2. Sensitive systems require deployment flexibility. On-premise, offline, air-gapped, hybrid-cloud and edge deployment patterns must be part of the original architecture.
    3. Auditability is as important as accuracy. Investigative and regulatory systems require provenance, chain of custody, role-based access, human review and reproducible results.
    4. Shared capabilities create national scale. Document intelligence, entity correlation, language processing, geospatial analysis and case management should not be procured repeatedly by separate departments.
    5. Sovereignty ultimately depends on people. A system is not sovereign if local engineers cannot operate, secure, modify and recover it without continuous external dependence.
    9. Proposed Shadgunya contribution in Cyprus
    Shadgunya looks forward to adapting these field-tested engineering patterns to Cyprus under European legal, ethical and institutional requirements. We do not propose transferring Indian systems or operating models unchanged. The objective would be to co-develop Cyprus-owned, EU-aligned capabilities with local government, universities, research institutions and industry.
    Potential areas of collaboration include:
    ● Designing the National Sovereign AI Reference Architecture.
    ● Establishing a secure multi-model government AI platform.
    ● Developing specialised sovereign models for regulated sectors.
    ● Creating an AI cybersecurity, red-team and assurance environment.
    ● Supporting financial-crime, AML and fraud-intelligence applications.
    ● Building critical-infrastructure, maritime and national-resilience analytics.
    ● Developing offline and edge AI for sensitive government operations.
    ● Training Cypriot engineers, AI Officers and security professionals.
    ● Establishing joint R&D in RISC-V security, sovereign chiplets, SLMs and secure edge AI.
    ● Creating locally anchored IP and export-ready products from Cyprus.
    An initial programme could begin with three lighthouse implementations: a reusable government knowledge and document-intelligence platform, a regulated financial-crime and compliance platform, and an AI security and critical-infrastructure monitoring capability.
    Conclusion
    Cyprus has an opportunity to become more than a consumer of foreign AI services. It can become a European centre for the design, assurance and export of sovereign AI systems for governments and regulated industries.
    The Strategy provides the right direction. Its next iteration should define exactly what Cyprus must control, what it will build nationally, what it will access through Europe, and what every supplier must transfer to the Cypriot ecosystem.
    Shadgunya Technologies looks forward to establishing a Cyprus-based sovereign AI engineering, assurance and productisation capability. Our objective is to adapt experience gained from operational government, defence, investigative and cybersecurity projects in India; co-develop these capabilities within Cyprus; ensure alignment with European rights and regulatory frameworks; and use Cyprus as the base from which trusted sovereign AI products can be delivered across Europe.

  7. Αρ. Άρθρου: 
    3.9 Ethics, Trust and Responsible AI

    Σχόλιο:
    An intersectionally diverse and representative taskforce/cohort of contributors must be ensured with regard to any AI policymaking and governance on a national level. 

    Αιτιολόγηση σχολίου / Εισήγησης: 
    The section rightly highlights the importance of ethics, accountability, fairness, transparency, and safeguarding societal values, achieving these goals requires a task force that genuinely reflects all stakeholders and the diversity of Cypriot society. A homogeneous, male-dominated cohort composed primarily of Greek/Greek Cypriots, academic institutions, and private corporations should be avoided. Such narrow governance inevitably skews the values and priorities driving national AI policymaking, which in turn can have considerable political impact on a national level.

    A lack of diversity creates policy blind spots and reinforces systemic inequalities that dominant groups can overlook. This issue is particularly critical for AI technologies, which have been proven to exacerbate inequality and further marginalise vulnerable communities across various global contexts, especially when deployed in the public sector, healthcare, recruitment, and law enforcement. In Cyprus, initial research indicates that the most vulnerable groups of the island (such as low-skilled workers, ethnic and sexual minorities, people with disabilities, migrants, and asylum seekers) may face the highest risk of AI-related harm. 

    Instead, having a cohort that is inclusive in terms of gender, ethnicity, and discipline (including civil society, labour unions, etc) can contribute towards ensuring human rights, fairness and equity, particularly taking the local Cypriot context into consideration. It also ensures that the values and priorities driving AI governance in Cyprus will not be limited to benefitting only a small, dominant section of society. It is recommended that the formation of diverse and inclusive cohorts is embedded directly into the government’s strategic AI planning, and be formally integrated within the Cypriot AI strategy and policymaking infrastructure.

  8. CONTRIBUTION TO THE PUBLIC CONSULTATION ON THE NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY 2032

    Submitted by:
    Andreas Kazamias
    Founder, Platanus Services Ltd, Cyprus
    Managing Director EMEA, Liberty IT Consulting Group, Australia

    Date: 29 August 2026

    Article / Section concerned

    National AI Strategy 2032 as a whole, with particular reference to Sections 1.4, 3.2–3.13, 4–5 and Annexes A–F.

    Comment / Recommendation

    It is encouraging to see Cyprus develop a National AI Strategy and make it available for public consultation. The Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist for Research, Innovation and Technology, the National AI Taskforce and all those involved in preparing the Strategy should be congratulated.

    The Strategy is ambitious and identifies many of the capabilities Cyprus will require. The principal opportunity before it is finalised is to strengthen the connection between vision, strategic choice and execution.

    My principal recommendations are:

    1. Sharpen prioritisation.
    Cyprus should distinguish between capabilities it must maintain nationally, a limited number of areas where it intends to develop internationally differentiated capability, and capabilities that can be accessed more effectively through European or international partnerships. Possible areas for further assessment include AI assurance and regulatory science, AI for island, climate and resource resilience, and maritime and shipping applications.

    2. Define AI sovereignty more practically.
    Full technological self-sufficiency is neither realistic nor necessary. For Cyprus, sovereignty should mean retaining control over critical data and functions, sufficient technical knowledge, interoperability, portability, contractual rights and credible alternative suppliers.
    Sovereignty should mean retaining the capacity to choose, not restricting the technologies from which Cyprus can choose.

    3. Link public-sector AI to measurable benefits.
    AI creates additional technology, training, governance and operating costs. Every material public-sector AI programme should therefore identify the capacity expected to be released, the full lifecycle cost and how the benefit will be realised through improved services, redeployment, avoided future recruitment, reduced cost or other measurable public value.
    AI deployment is an activity. Realised public value is the outcome.

    4. Redesign processes before automating them.
    AI should not simply automate existing administrative procedures. Major projects should first simplify processes, eliminate unnecessary approvals and duplicated information requirements, improve data reuse and review workforce responsibilities.
    AI should not automate yesterday’s bureaucracy.

    5. Make ethics operational.
    Ethical principles should be implemented through risk assessment, accountable ownership, testing, documentation, monitoring, incident management and redress. Ethics committees may provide valuable specialist challenge but should not substitute for lifecycle governance. The several ethics-related bodies referred to in the Strategy should also be reconciled and given clear Terms of Reference.

    6. Clarify human oversight.
    Human-centred AI should preserve accountability and meaningful human intervention in appropriate circumstances, but should not necessarily require a human to repeat every routine AI-supported assessment. Human-in-command does not require human-in-every-transaction.

    7. Establish a proportionate private-sector AI governance pathway.
    The Strategy provides detailed governance for government but less operational guidance for ordinary enterprises and SMEs. NAICF Comply and AdoptNAICF could provide the basis for a horizontal private-sector framework rather than appearing primarily within Legal Services.

    8. Clarify the State’s role in Financial Services and Financial Technology.
    Several proposed use cases are principally matters for individual financial institutions. The National Strategy should concentrate on what Cyprus can provide collectively that institutions cannot efficiently provide themselves: coordinated regulatory pathways, appropriate sandboxes, skills, assurance, shared mechanisms where justified, RegTech and SupTech capability and FinTech ecosystem development.

    9. Extend data governance beyond access.
    The Strategy should address not only who may access public data, but also who may derive models, embeddings, inferred information or other intellectual property from it, on what terms, and who retains the resulting capability.

    10. Simplify institutional and sandbox architecture.
    Regulatory sandboxes, technical test environments, secure data environments and physical testbeds serve different purposes. Cyprus should avoid creating parallel sector structures where common national capability with specialist participation would suffice. Similarly, Centres of Excellence should strengthen existing universities, research organisations and private capability rather than unnecessarily duplicate them.

    11. Clarify specific governance ambiguities.
    These include the reporting line and authority of ministry AI Officers; the distinction between development, testing, assurance and formal certification; the relationship between private Legal Services and judicial or public-sector AI; and the status of testing performed by the proposed Industrial Centre of Excellence.

    12. Move measurement from indicative to operational.
    Annex F is a useful starting point, but each core KPI should define its baseline, target, methodology, source, accountable owner, reporting frequency and intervention threshold. Deployment should be distinguished from measurable outcomes.

    13. Apply a consistent evidential standard throughout.
    The Education and Human Capital Development section provides a useful example of detailed references and supporting evidence. Material numerical targets, international comparisons and statements of best practice elsewhere in the Strategy should be supported to the same standard.

    14. Address additional cross-cutting implementation issues.
    The final Strategy should also consider the role of open-source and open-weight AI, contractual allocation of AI procurement risk, retention and traceability of AI-assisted public records, and the risk of excessive concentration around a small number of cloud, model and systems-integration providers.

    Justification

    Cyprus does not need to lead in every field of Artificial Intelligence. Its size can instead become an advantage if the country is clear about where it intends to lead, where it requires sufficient national capability, and where European and international collaboration will produce better results.

    The Strategy already contains much of the necessary foundation. The recommendations above are intended primarily to make the final document more selective, operational and measurable: clearer choices, clearer ownership, realistic sequencing and resources, and a stronger connection between AI investment and demonstrable national benefit.

    A full submission has also been provided separately in PDF form. It is structured in three parts: the Main Response, setting out the principal strategic observations and recommendations; a detailed Appendix, containing section- and page-specific observations and recommendations against the National AI Strategy; and a Sources and References section supporting the analysis. This structure allows the broader strategic recommendations to be considered alongside the specific provisions of the Strategy to which they relate.

    The PDF should therefore be read together with this summary as the complete contribution to the consultation.

  9. Section 3.11 “Measuring Impact and National KPIs”
    Suggestion:
    Enhance the existing KPI framework by establishing a comprehensive National AI Performance Scorecard supported by a formal measurement governance structure. Each KPI should be accompanied by a clear definition, baseline value, target trajectory, data source, accountable owner, reporting frequency, calculation methodology, dependencies, and escalation criteria. Furthermore, the scorecard should differentiate between implementation metrics (such as training programmes delivered, AI pilots completed, or digital services enhanced) and impact metrics (such as productivity gains, AI adoption rates, citizen trust, investment attraction, economic contribution, and societal outcomes).
    Justification:
    The strategy identifies several key dimensions for measuring success, including AI adoption, public sector transformation, talent development, trust, compliance, and economic impact. However, the absence of a structured measurement governance framework may limit the ability to consistently monitor progress and assess the effectiveness of strategic initiatives. A comprehensive performance scorecard would improve transparency, accountability, and evidence-based decision-making by ensuring that all stakeholders operate against a common set of measurable objectives. Clearly defined baselines, ownership responsibilities, and escalation mechanisms would facilitate early identification of underperforming initiatives and support timely corrective actions. This would strengthen the overall governance of the strategy and provide greater confidence that reported progress reflects tangible national outcomes rather than activity levels alone.

    Section 3.3, “Governance and Controls”
    Suggestion:
    Introduce a detailed Roles, Responsibilities and Decision-Making Framework that clearly defines the responsibilities, accountabilities, consultation requirements, and reporting obligations of all governance and delivery stakeholders involved in the implementation of the National AI Strategy. The framework should specify governance interactions across the National AI Authority, the responsible Ministry or Deputy Ministry, the Interministerial AI Council, specialised advisory committees, delivery organisations, regulators, public sector entities, research institutions, local authorities, and private-sector partners.
    Justification:
    The strategy establishes a robust multi-layer governance structure; however, the practical interaction between the various bodies and stakeholders is not always fully defined. As AI initiatives frequently span multiple policy areas, organisations, and sectors, unclear accountability arrangements may lead to overlapping responsibilities, duplication of effort, delayed decision-making, and implementation challenges. A formal governance and decision-making framework would provide greater clarity regarding ownership of strategic initiatives, funding decisions, risk management, regulatory oversight, and benefit realisation. It would also improve coordination across stakeholders, strengthen accountability for delivery milestones and outcomes, and support more effective escalation and resolution of implementation issues. Ultimately, this would enhance the efficiency and effectiveness of the strategy’s execution and increase the likelihood of achieving its long-term objectives.

    Section 3.10.3 “Funding and Renewal Model ”
    Suggestion:
    Introduce a dedicated, multi-year budget and funding framework for the implementation of the National AI Strategy, including indicative budgets per strategic pillar, funding sources, responsible authorities, and annual allocation mechanisms.
    Justification:
    While the strategy establishes a clear vision, objectives, and initiatives, it does not provide sufficient visibility regarding the financial resources required to achieve them. Successful implementation of national AI programmes requires sustained investment in digital infrastructure, data platforms, skills development, research and innovation, public sector transformation, cybersecurity, and governance mechanisms. Without a dedicated budget, there is a risk that strategic initiatives will be delayed, scaled back, or implemented inconsistently across government entities. A defined funding framework would enhance accountability, facilitate long-term planning, improve stakeholder confidence, and enable the government to leverage European Union funding programmes and private sector co-investment more effectively.

    Section 1.5 “Implementation Timeline and Success Metrics”
    Suggestion:
    Develop a detailed implementation roadmap with clear milestones, timelines, deliverables, responsible organisations, dependencies, and key performance indicators (KPIs) covering the period up to 2032.
    Justification:
    The strategy outlines strategic priorities and desired outcomes but would benefit from a more structured execution plan. A roadmap with phased milestones (short-term, medium-term, and long-term) would provide clarity on implementation priorities and sequencing of activities. It would also enable monitoring of progress, facilitate coordination among government entities, academia, and industry, and allow early identification of implementation challenges. Furthermore, measurable milestones would support transparent reporting to stakeholders, strengthen governance, and ensure that progress towards the strategy’s objectives can be objectively assessed and adjusted where necessary. Such an approach aligns with international best practices for national digital and AI strategies and increases the likelihood of achieving the intended outcomes by 2032.

  10. The below 8 recommendations focus on tangible amendments that can strengthen the Strategy’s implementation, accountability, business adoption and investment attractiveness.

    1. Costed implementation and investment plan
    Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.5, 3.10, 3.11 and 5; Annex F.

    Σχόλιο / Εισήγηση:
    Within 90 days of the Strategy’s adoption, an Implementation and Investment Plan should be approved and published.
    For every strategic initiative, the Plan should identify the accountable owner, delivery milestones, budget range, funding source, dependencies, procurement route, measurable KPIs and continuation or exit criteria.

    Αιτιολόγηση σχολίου / Εισήγησης:
    The Strategy includes several ambitious initiatives and timelines, but many do not yet have an identified owner, budget, funding route or measurable delivery condition.
    A single costed implementation portfolio would support effective prioritisation, prevent duplication and enable transparent monitoring of delivery, expenditure and public value.

    2. Separation of delivery and statutory supervision
    Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.4.3, 3.3.1, 3.9.6 and 4.3; Annex A.

    Σχόλιο / Εισήγηση:
    The final Strategy should clearly distinguish the Strategy owner and delivery office from the competent authorities responsible for market surveillance, conformity assessment, data protection, cybersecurity and sectoral regulation.
    No organisation should simultaneously fund or develop AI solutions and provide binding assurance, certification or enforcement concerning those same solutions.

    Αιτιολόγηση σχολίου / Εισήγησης:
    Clear institutional separation protects regulatory independence, avoids conflicts of interest and provides businesses with greater legal and regulatory certainty.
    Innovation support, regulatory sandboxes and pre-compliance guidance are valuable functions, but they should not be confused with statutory supervision, certification or enforcement under the EU AI Act and existing national law.

    3. Measurable and consistent national targets
    Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.5, 2.5 and 3.11; Annex F.

    Σχόλιο / Εισήγηση:
    For every national KPI, the final Strategy should define:
    * The baseline year and value.
    * The calculation formula.
    * The authoritative data source.
    * The accountable owner.
    * The reporting frequency.
    * The annual target trajectory to 2032.
    Any inconsistent adoption percentages or target dates should be reconciled. GDP and productivity estimates should be presented as scenarios until independently validated.

    Αιτιολόγηση σχολίου / Εισήγησης:
    Targets cannot guide investment or demonstrate impact unless they are clearly and consistently defined.
    A public KPI register, updated at least annually, would allow government, businesses and society to distinguish measurable outcomes from activity indicators such as the number of pilots, tools purchased or people attending training.

    4. Mandatory data-readiness control gate
    Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 2.2.2 and 3.2.2; Section 5; Annex B, Control Gates 1 and 2.

    Σχόλιο / Εισήγηση:
    The Strategy should establish a target publication date for the National Data Policy and the National Data Governance Framework.
    Before the procurement, funding or scaling of any public-sector AI use case, the responsible organisation should be required to demonstrate:
    * An identified data owner.
    * A documented lawful basis.
    * Defined data-quality thresholds.
    * Data classification, metadata and lineage.
    * Retention and access-control requirements.
    * Confirmed availability of the required data.
    This should become an explicit requirement within the Strategy’s AI use-case control gates.

    Αιτιολόγηση σχολίου / Εισήγησης:
    AI projects frequently fail or underperform because the required data is unavailable, unreliable, incomplete or not lawfully usable.
    A mandatory data-readiness gate would prevent premature procurement, reduce rework and ensure that pilots are selected because they can deliver measurable outcomes—not merely because the technology is available.

    5. Investment-compatible definition of AI sovereignty
    Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.1, 1.2-National Strategic Objectives 6 and 8-1.4.6, 1.6 and 3.7.

    Σχόλιο / Εισήγηση:
    Expressions such as “controlling all critical layers” and general references to “foreign platforms” should be replaced with objective requirements relating to:
    * Effective governance and legal control.
    * Security and resilience.
    * Legal enforceability.
    * Interoperability and portability.
    * Operational continuity.
    * Supplier choice and exit capability.
    Cyprus-only or EU-only hosting requirements should apply only to clearly defined workloads where localisation is required by law or justified by a documented risk assessment.

    Suggested wording:
    “Cyprus will maintain effective governance, security, resilience and strategic choice across critical AI capabilities through secure architecture, interoperability, enforceable controls and trusted partnerships.”

    Αιτιολόγηση σχολίου / Εισήγησης:
    For a small and open economy, strategic autonomy should mean retaining effective control and choice while using trusted partnerships to obtain scale and specialist capabilities.
    Origin-based preferences or blanket localisation could increase costs, restrict access to innovation and create uncertainty for international investors without necessarily improving security or resilience.

    6. Avoidance of duplicative national certification and registration
    Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 3.9.6 and 4.3; Annex A.

    Σχόλιο / Εισήγηση:
    The EU AI Act should remain the principal regulatory baseline.
    The Strategy should not introduce mandatory national AI certification, universal registration of AI systems or duplicate documentation requirements unless these are supported by a specific legal basis and a demonstrated need.
    Compulsory registration should be limited to requirements arising from EU or national law and to proportionate transparency obligations concerning material public-sector AI systems.
    Cyprus should instead provide voluntary pre-compliance assessments and coordinated regulatory guidance through a one-stop service.

    Αιτιολόγηση σχολίου / Εισήγησης:
    Additional national regulatory layers could fragment the EU Single Market, delay product launches and impose disproportionate costs on Cypriot SMEs.
    Cyprus can create a genuine competitive advantage through clear guidance, rapid regulatory navigation and credible assurance capabilities rather than through duplicative national obligations.

    7. Technology-neutral AI procurement and IP protection
    Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.4.3, 3.4 and 4.2; Annex B and Annex C-Government and Public Sector.

    Σχόλιο / Εισήγηση:
    The Strategy should provide for the publication of standard AI procurement clauses covering:
    * Outcome-based specifications.
    * Total lifecycle cost.
    * Data and model rights.
    * Data and model provenance.
    * Security and auditability.
    * Model changes and performance drift.
    * Interoperability and portability.
    * Incident response and business continuity.
    * Supplier transition and exit.
    Procurement terms should clearly distinguish pre-existing supplier intellectual property from project-created intellectual property.
    Model weights, source code, trade secrets and cybersecurity-sensitive information should be protected through proportionate audit and assurance arrangements.

    Αιτιολόγηση σχολίου / Εισήγησης:
    Public procurement will play an important role in shaping Cyprus’s AI market.
    Clear, transparent and technology-neutral requirements would reduce supplier lock-in, allow Cypriot SMEs and international providers to compete fairly and protect legitimate public oversight.
    They would also avoid discouraging companies from bringing proprietary technology, investment or research and development activity to Cyprus.

    8. One practical pathway for business adoption and investment
    Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 3.6, 3.8, 4.4 and 5; Annex C-Entrepreneurship and Innovation.

    Σχόλιο / Εισήγηση:
    A single, coordinated AI business-adoption and investor pathway should be established, combining:
    * AI readiness assessment.
    * Regulatory and compliance triage.
    * Standard documentation and templates.
    * Access to regulatory sandboxes.
    * Vouchers or co-funding.
    * Access to computing resources.
    * Connections with universities and research organisations.
    * Talent and relocation guidance.
    * Access to public-sector and private-sector pilots.
    * Commercialisation and export support.
    Each business or investor should have one accountable case manager, supported by published service standards and response times.
    The programme should measure productivity gains, exports, investment, skilled employment and successful scaling, not only participation or the number of supported projects.

    Αιτιολόγηση σχολίου / Εισήγησης:
    Businesses currently risk having to navigate multiple organisations, funding schemes and regulatory processes independently.
    A coordinated pathway would reduce adoption barriers for SMEs, improve Cyprus’s investor experience and convert the Strategy’s ecosystem ambition into measurable commercial outcomes.

  11. Comments on the Healthcare and Life Sciences pillar
    Submitted by: Denis Losik, PhD Cardiologist, CMO of eMed Support Systems, Limassol registered company
    28.08.2026

    COVER NOTE
    We welcome the Healthcare and Life Sciences pillar, particularly its commitments to data in standards of HL7 FHIR, SNOMED CT, and ICD, as well as its alignment with European Health Data Space principles. We especially support its focus on clinician enablement through accountable AI, intelligent triage and care navigation, and patient-centric service improvement.
    The three comments below address one question: how the pillar’s 2032 ambitions for clinician enablement, intelligent triage and care clinical decision support navigation become a dated, measurable program inside the GeSY within the Strategy’s own implementation windows.
    Declaration of interest:
    eMed Support Systems is a Cyprus-based AI-native platform that provides advanced analytics and clinical decision support for primary care physicians. The platform integrates with healthcare systems via FHIR/HL7 standards as a read-only layer, avoiding disruption to clinical workflows. By applying clinical guideline logic, the platform identifies patients who need attention and recommends next steps to the clinical team, supported by personalized care and population-level analytics.

    Annex C, Healthcare and Life Sciences (printed p. 68); Strategic objectives and 2032 target
    1) Suggestion/comments:
    The Healthcare and Life Sciences pillar could be strengthened by defining a near-term implementation pathway that links the Strategy’s objectives for clinician enablement, intelligent triage and care navigation with current priorities of GeSY.
    Recent analysis of the Cypriot health system identifies several areas where this implementation pathway could deliver early measurable value. These include using clinical data from the State Health Services Organization (SHSO) to support AI-enabled data processing, improve chronic disease management, reduce low-value specialist use, improve referral appropriateness, and provide the Health Insurance Organization with better evidence on population health needs, quality of care, and variation in care pathways. Such an approach could support Personal Doctors in making timely decisions and reducing the costs of chronic disease management.

    Annex C, Healthcare and Life Sciences (printed p 68) National frameworks and governance
    2) Suggestion/comments:
    Within the NeHA framework, a dedicated regulatory framework could be developed to address key challenges related to data interoperability and exchange processes. This framework should draw on documents and standards already developed under the EHDS and should be aligned with Regulation (EU) 2025/327 on the European Health Data Space in the Healthcare pillar’s governance provisions, and align the national framework with Article 53 of that Regulation, which sets out the purposes for which electronic health data may be processed for secondary use. Those purposes include scientific research in the health or care sector, including development and innovation activities for products or services and the training, testing and evaluation of algorithms; and the provision of personalized healthcare.
    At a later stage, subject to the applicable regulatory and clinical-governance requirements, patient-level decision-support capabilities could be introduced into Personal Doctor workflows to support treatment decisions, investigations, prioritization and indications for specialist referral, while preserving clinical accountability. The sandbox for AI-enabled products should be organized under the NeHA regulation and the data access regulation.
    National IT infrastructure should be required to ensure the secure and sovereign use of AI with data from the National Health Data Repository. This should include an evaluation of the computing, storage, interoperability, and security resources needed to process health data at the national level.
    The Task Force should also explore potential technical cooperation with cloud and AI infrastructure providers, such as Nebius, Google Cloud, Oracle, Microsoft Azure, and other relevant market participants. These discussions should focus on infrastructure design, data protection, scalability, cost, and compliance with national and EU requirements for the use of health data.
    Regulatory classification. Where the pilot advances, at a later stage and subject to clinical-governance requirements, to patient-level decision support in Personal Doctor workflows — treatment decisions, investigations, prioritisation, indications for referral — the Strategy should state that such a system is a medical device under Rule 11 of Annex VIII to Regulation (EU) 2017/745, Class IIa at minimum, requiring a notified body, and that EU AI Act obligations attach on top of that classification rather than in place of it.

    Annex C, Healthcare and Life Sciences (printed p 69). Implementation, evidence and compliance
    3) Suggestion/comments:
    A practical first step of implementation could be a controlled AI-enabled healthcare platform for a pilot in 2026/2027, consistent with the Strategy’s wider implementation timeline for launching pilots within 6-12 months and scaling successful use cases within 12-24 months.
    The pilot could focus on a defined high-burden chronic disease population, with cardiovascular disease and diabetes representing a suitable initial use case as one of the largest and most vulnerable patient cohorts. Its purpose would be to test whether routinely available healthcare data from GeSY or SHSO can be used to support:
    – systematic identification of population health needs and gaps in care;
    – measurement of guideline-based quality indicators and treatment-target attainment, creating a basis for future performance monitoring and Pay-4-Performance frameworks;
    – identification of variation in care pathways across providers and patient populations;
    – assessment of which patient groups can be appropriately managed in primary care and which meet predefined criteria for further investigation or specialist assessment;
    – more timely access to relevant clinical information for healthcare professionals and system planners.

    If validated, these capabilities could subsequently be scaled across GeSY to support continuous quality monitoring, stronger primary-care-led chronic disease management, more appropriate use of specialist services, evidence-based resource allocation and the development of performance-based reimbursement models, including Pay-for-Performance.

    Justification:
    This addition would provide a practical bridge between the Strategy’s 2032 healthcare ambitions and near-term implementation. It would also align the AI Strategy more closely with current priorities of the Cypriot health system. Recent WHO/European Observatory analysis, developed with the support of HIO, identifies underuse of primary care, overuse of outpatient specialist care, weaknesses in the gatekeeping role of Personal Doctors, variation in referral pathways, and limited availability of population-health and performance data. It highlights the need for stronger health information systems, routine population-health analysis, quality and performance indicators, and AI-native decision-support tools for Personal Doctors.
    The scale of the utilization challenge is significant. Cyprus residents make approximately 8.7 physician visits per year, including 4.3 outpatient specialist visits, while cardiology alone accounted for approximately 320,000 specialist visits in 2024. Strengthening Personal Doctors and reducing low-value specialist care are therefore directly relevant to both health-system efficiency and quality of care.
    A phased implementation pathway could be assessed against clear system-level outcomes, including:
    – higher healthcare workforce productivity, through faster analysis of longitudinal patient information and more efficient identification of relevant patient cohorts;
    – more appropriate triage and referral, helping Personal Doctors manage suitable patients within primary care while directing higher-risk or complex patients to specialist care;
    – educed low-value specialist utilization and unnecessary follow-up, particularly in high-burden chronic disease populations;
    – continuous quality and performance monitoring, enabling HIO to measure treatment-target achievements, guideline adherence and agreed clinical KPIs, and providing a stronger knowledge for performance-based reimbursement, Pay-for-Performance and strategic purchasing;
    – better chronic disease outcomes and lower downstream utilization, including avoidable specialist care and hospitalizations, to be measured prospectively during pilot and scale-up phases.

    Defining these outcomes at the outset would support the Strategy’s broader objective of progressing from isolated AI experimentation toward demonstrable public value. Successful healthcare use cases could subsequently be integrated with the planned Secure National Health Data Repository, in alignment with NeHA regulations for the Digital Healthcare Twin, the Virtual AI Patient Orchestrator, and preparations for EHDS infrastructure. This would help ensure that national investments in data and AI translate into measurable improvements in care delivery, quality, and resource utilization.

  12. The document/strategy is good but in many places it reads generic. To avoid this, it could shorten/omit some of the generics giving emphasis to the local Cypriot dimension.
    I would also like to offer the following (five) specific suggestions.

    A) Healthcare and Education are missing from the vision part of the document.

    B) The emphasis on a human-center perspective in the national vision is commendable but this does not resonate in the document.
    Also, we need to remember that at present the technology does not admit the tools that would help companies to easily develop systems that are transparent and compliant by design. Asking for systems that are proactively designed for ethical fairness requires strong regulation from EU which alas is not forthcoming.
    The only way to provide some such guarantees is with a strong “human in the loop” element, as the document points out. The strategy could include actions that would support this:
    Suggestion: Set up instruments to support a continuous consultation with the stakeholders and the general public before, during and after the development of AI systems.

    C) The national strategy needs to focus on the local reality of the reach of the capabilities of Cyprus. AI has not yet proved that it can provide growth and acceleration of productivity, especially in small and medium scale companies. In Cyprus, we cannot sustain infrastructure for large-scale AI and its applications.
    Putting the emphasis on the local reality the major related strength of Cyprus is its human resource, particularly within the younger age. AI is an innovation enabler amongst young fresh ideas. Cyprus could set up the aim to create an ever-increasing innovation culture in its society. One suggested action for this the following.
    Suggestion: The government can expand its scheme for setting up and funding AI (and other types) start-up companies whose founders are young entrepreneurs.
    The scheme should be aggressive in recruiting interest and setting up the startups, with little interference from the funding department, expect to monitor that the companies are taking mentor advice on the business side of start-up companies. The government funding could be generous so that the 2-3 young founders can work full time to set up their innovation and move to the next level of investment funding.

    D) Another local advantage is the high-density of medical experts (doctors and others) together researchers in medical informatics and AI. AI can help put together solutions to medical needs that are sensitive to local data that at the same time can form proof of principle solutions for other EU countries.
    Suggestion: Create an environment to foster working collaborations targeted on specific local healthcare needs.

    E) Regarding AI & Education the challenge is complex. Nevertheless, it is paramount to have a reform in the educational system where emphasis is put on language and dialectic critical thinking skills. AI is turning Natural Language into a Technology Language. For details of our suggestion on this reform see:
    https://paideia-news.com/i-texniti-noimosyni-epanaprosdiorizei-tin-ekpaideysi

  13. ΣΧΟΛΙΟ 5 — AI-enabled Built Environment and Permitting Pilot
    Αρ. Άρθρου και εδαφίου
    Annex C — Government and Public Sector / Priority Sectors · 3.11 Measuring Impact and National KPIs
    Σχόλιο / Εισήγηση
    Να εξεταστεί η δημιουργία πιλοτικής δράσης “AI-enabled Built Environment and Permitting Pilot”, με αρχική εφαρμογή σε περιορισμένο και ελεγχόμενο πεδίο.
    Η πιλοτική δράση προτείνεται να αναπτυχθεί σε τρεις συνδεδεμένους άξονες:
α) Planning and Building Permitting,
β) Construction Safety and Inspection, και
γ) Building Lifecycle and Energy Renovation.
    Η εφαρμογή να πραγματοποιηθεί με ανθρώπινη εποπτεία και να αξιολογηθεί βάσει προκαθορισμένων και μετρήσιμων δεικτών, μετά την καταγραφή των αντίστοιχων υφιστάμενων δεδομένων αναφοράς.
    Αιτιολόγηση σχολίου / Εισήγησης
    Ο τομέας του δομημένου περιβάλλοντος προσφέρει κατάλληλο πεδίο πιλοτικής εφαρμογής ΤΝ, επειδή περιλαμβάνει συγκεκριμένες διοικητικές και τεχνικές διαδικασίες, σημαντικό όγκο δεδομένων και δυνατότητα αντικειμενικής μέτρησης των αποτελεσμάτων.
    Στον άξονα της αδειοδότησης μπορούν να αξιολογηθούν εφαρμογές για τον αρχικό έλεγχο πληρότητας, την επεξεργασία εγγράφων και σχεδίων, την υποστήριξη ελέγχου και τη διαχείριση υποθέσεων.
    Στον άξονα της κατασκευής και επιθεώρησης μπορούν να εξεταστούν εφαρμογές computer vision, risk analytics, ψηφιακής τεκμηρίωσης, καταγραφής ελαττωμάτων και υποστήριξης θεμάτων ασφάλειας και υγείας.
    Στον κύκλο ζωής των κτιρίων μπορούν να εξεταστούν εφαρμογές BIM, digital twins, ενεργειακής απόδοσης, predictive maintenance και υποστήριξης προγραμμάτων ανακαίνισης και ενεργειακής αναβάθμισης.
    Πριν από τον καθορισμό ποσοτικών στόχων πρέπει να καταγραφούν τα υφιστάμενα δεδομένα αναφοράς. Στη συνέχεια μπορούν να καθοριστούν δείκτες όπως ο χρόνος αρχικού ελέγχου πληρότητας, ο συνολικός χρόνος διεκπεραίωσης, ο αριθμός επαναλαμβανόμενων παρατηρήσεων, η ακρίβεια των επισημάνσεων του συστήματος, το ποσοστό ανθρώπινης παράκαμψης εισηγήσεων ΤΝ και ο αριθμός επαγγελματιών και τεχνικών που καταρτίστηκαν.
    Η πιλοτική εφαρμογή θα επιτρέψει την αξιολόγηση της πραγματικής αποτελεσματικότητας, του κόστους, των κινδύνων και της δυνατότητας επέκτασης πριν από οποιαδήποτε εφαρμογή σε μεγαλύτερη κλίμακα.

  14. ΣΧΟΛΙΟ 4 — ΤΝ στην πολεοδομική και οικοδομική αδειοδότηση / ΙΠΠΟΔΑΜΟΣ
    Αρ. Άρθρου και εδαφίου
    3.4.1 Priority Areas for Government Adoption · 3.4.2 Prioritization of AI Use Cases · Annex C — Government and Public Sector
    Σχόλιο / Εισήγηση
    Να συμπεριληφθούν η πολεοδομική και οικοδομική αδειοδότηση, ο οικοδομικός έλεγχος και η επιθεώρηση κατασκευών ως συγκεκριμένη οικογένεια περιπτώσεων χρήσης ΤΝ στον δημόσιο τομέα.
    Προτείνεται η ανάπτυξη εφαρμογών AI-assisted decision support, με αξιοποίηση και διασύνδεση με την υφιστάμενη ψηφιακή υποδομή αδειοδότησης, περιλαμβανομένου του συστήματος ΙΠΠΟΔΑΜΟΣ, χωρίς αντικατάσταση της τελικής ανθρώπινης και διοικητικής κρίσης.
    Αιτιολόγηση σχολίου / Εισήγησης
    Η πολεοδομική και οικοδομική αδειοδότηση αποτελεί διαδικασία με μεγάλο όγκο αιτήσεων, σχεδίων, πιστοποιητικών, τεχνικών εκθέσεων και λοιπών εγγράφων, τα οποία αξιολογούνται έναντι καθορισμένων απαιτήσεων.
    Προσφέρεται συνεπώς για εφαρμογές ΤΝ που μπορούν να υποστηρίζουν τον αρχικό έλεγχο πληρότητας του φακέλου, την εξαγωγή δομημένων δεδομένων από αιτήσεις και τεχνικά έγγραφα, την υποβοήθηση ανάγνωσης σχεδίων, τον εντοπισμό αντιφάσεων μεταξύ υποβαλλόμενων στοιχείων, την επισήμανση πιθανών αποκλίσεων προς περαιτέρω έλεγχο και την ταξινόμηση και δρομολόγηση υποθέσεων.
    Αντίστοιχες εφαρμογές μπορούν να υποστηρίζουν τον προγραμματισμό επιθεωρήσεων βάσει κινδύνου, την ψηφιακή τεκμηρίωση επιτόπιων ελέγχων και την καταγραφή ελαττωμάτων.
    Η ΤΝ πρέπει να λειτουργεί υποστηρικτικά και όχι ως μηχανισμός αυτόματης έκδοσης διοικητικών αποφάσεων. Η τελική διοικητική κρίση πρέπει να παραμένει στην αρμόδια αρχή και η επαγγελματική ευθύνη των αδειούχων μελετητών να διατηρείται για τις μελέτες και πιστοποιήσεις που εμπίπτουν στην αρμοδιότητά τους.
    Η εφαρμογή μπορεί να δημιουργήσει μετρήσιμη δημόσια αξία μέσω της μείωσης του διοικητικού φόρτου, της ταχύτερης επεξεργασίας των αιτήσεων και της βελτίωσης της συνέπειας των αρχικών ελέγχων.
    Οι δυνατότητες document intelligence, case routing και compliance support που θα αναπτυχθούν μπορούν επιπλέον να επαναχρησιμοποιηθούν σε άλλες διαδικασίες αδειοδότησης του δημόσιου τομέα, σύμφωνα με την αρχή “Build Once, Reuse Everywhere”.

  15. ΣΧΟΛΙΟ 3 — FutureAI CY, ΑνΑΔ και επαγγελματικά προσόντα
    Αρ. Άρθρου και εδαφίου
    Annex C — Education and Human Capital Development (FutureAI CY) · 3.3.1.7 National AI Skills Observatory
    Σχόλιο / Εισήγηση
    Να δημιουργηθεί στο FutureAI CY ειδική διαδρομή μάθησης για τις Κατασκευές και το Δομημένο Περιβάλλον, αξιοποιώντας, όπου είναι θεσμικά κατάλληλο, την υφιστάμενη υποδομή επαγγελματικής κατάρτισης και το Σύστημα Επαγγελματικών Προσόντων της ΑνΑΔ.
    Να εξεταστεί η αντιστοίχιση και συμπληρωματικότητα των νέων AI micro-credentials με το CyQF/EQF και τα υφιστάμενα επαγγελματικά προσόντα.
    Παράλληλα, να συμπεριληφθούν τα επαγγελματικά προφίλ των Κατασκευών και του Δομημένου Περιβάλλοντος στον Cyprus AI Skills Gap Atlas του National AI Skills Observatory.
    Αιτιολόγηση σχολίου / Εισήγησης
    Ο κατασκευαστικός τομέας αποτελεί κατάλληλο πεδίο εφαρμογής του FutureAI CY λόγω της παρουσίας πολύ μικρών και μικρών επιχειρήσεων, ρυθμιζόμενων επαγγελμάτων και μεγάλου αριθμού διαφορετικών τεχνικών ειδικοτήτων.
    Η Κύπρος διαθέτει ήδη οργανωμένη υποδομή επαγγελματικής κατάρτισης και αξιολόγησης επαγγελματικών προσόντων μέσω της ΑνΑΔ, με Κέντρα Επαγγελματικής Κατάρτισης, Κέντρα Αξιολόγησης Επαγγελματικών Προσόντων, εκπαιδευτές και αξιολογητές.
    Η αξιοποίηση της υφιστάμενης υποδομής μπορεί να επιταχύνει τη διάχυση δεξιοτήτων ΤΝ στον κατασκευαστικό τομέα και να περιορίσει την ανάγκη δημιουργίας παράλληλων μηχανισμών.
    Προτείνεται συνεπώς να εξεταστεί θεσμικά η αντιστοίχιση και συμπληρωματικότητα των νέων micro-credentials με το υφιστάμενο πλαίσιο CyQF/EQF και τα σχετικά επαγγελματικά προσόντα, όπου αυτό είναι εφικτό.
    Η προσέγγιση αυτή συνάδει με την αρχή “Build Once, Reuse Everywhere” της Στρατηγικής, εφαρμοζόμενη και στην υφιστάμενη υποδομή ανάπτυξης ανθρώπινου κεφαλαίου.

  16. ΣΧΟΛΙΟ 2 — Εξειδικευμένες δεξιότητες ΤΝ για τις Κατασκευές
    Αρ. Άρθρου και εδαφίου
    2.5.5 Objective 5: Develop, attract and retain AI-related skills and talent · 3.6.2 Advanced and Sector-Specific Skills
    Σχόλιο / Εισήγηση
    Να προστεθούν οι Κατασκευές και το Δομημένο Περιβάλλον στους τομείς για τους οποίους προβλέπεται ανάπτυξη εξειδικευμένων και προσαρμοσμένων δεξιοτήτων ΤΝ.
    Προτείνεται η ανάπτυξη διακριτών επιπέδων κατάρτισης για:
α) μηχανικούς και άλλους επαγγελματίες του δομημένου περιβάλλοντος, και
β) τεχνικό, εποπτικό και εργατικό προσωπικό του κατασκευαστικού τομέα.
    Αιτιολόγηση σχολίου / Εισήγησης
    Η Ενότητα 3.6.2 συνδέει τις απαιτούμενες δεξιότητες ΤΝ με το ειδικό επαγγελματικό και ρυθμιστικό πλαίσιο κάθε τομέα. Οι Κατασκευές αποτελούν έντονα ρυθμιζόμενο επαγγελματικό και τεχνικό περιβάλλον, στο οποίο εμπλέκονται μηχανικοί διαφορετικών κλάδων, μελετητές, εργολήπτες, επιβλέποντες, τεχνικό προσωπικό και δημόσιες αρχές.
    Η χρήση ΤΝ μπορεί να αφορά BIM και digital twins, ανάλυση σχεδίων και τεχνικών εγγράφων, επιμετρήσεις, εκτίμηση κόστους, προγραμματισμό έργων, υποστήριξη ελέγχου κανονιστικής συμμόρφωσης, διαχείριση συμβάσεων, επιθεωρήσεις, καταγραφή ελαττωμάτων και θέματα ασφάλειας και υγείας.
    Η κατάρτιση δεν πρέπει να περιορίζεται στη χρήση γενικών εργαλείων ΤΝ. Πρέπει να περιλαμβάνει αξιολόγηση της αξιοπιστίας των αποτελεσμάτων, αναγνώριση εσφαλμένων ή μη τεκμηριωμένων αποτελεσμάτων, προστασία προσωπικών και εμπιστευτικών δεδομένων, επαγγελματική ευθύνη και καθορισμό των περιπτώσεων στις οποίες απαιτείται ανθρώπινη επαλήθευση.
    Παράλληλα, το εργατικό δυναμικό του κλάδου παρουσιάζει σημαντική διαφοροποίηση ως προς την τυπική εκπαίδευση, τις ψηφιακές δεξιότητες και τη γλωσσική επάρκεια. Απαιτούνται συνεπώς διαφορετικά επίπεδα και μορφές κατάρτισης, προσαρμοσμένα στις πραγματικές ανάγκες κάθε επαγγελματικής ομάδας.

  17. ΣΧΟΛΙΟ 1 — Κατασκευές και Δομημένο Περιβάλλον ως Τομέας Προτεραιότητας
    Αρ. Άρθρου και εδαφίου
    1.3 Priority Sectors for Leadership · 2.4.1 Priority Sectors for Leadership
    Σχόλιο / Εισήγηση
    Να προστεθεί ο τομέας Κατασκευών και Δομημένου Περιβάλλοντος (Construction and Built Environment) στους Τομείς Προτεραιότητας της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη.
    Σε περίπτωση που διατηρηθεί ο υφιστάμενος αριθμός των οκτώ Τομέων Προτεραιότητας, προτείνεται, ως εναλλακτική, η ρητή αναγνώριση των Κατασκευών και του Δομημένου Περιβάλλοντος ως αυτοτελούς οριζόντιου τομέα εφαρμογής, με καθορισμένο φορέα συντονισμού, συγκεκριμένες δράσεις και μετρήσιμους δείκτες αποτελέσματος.
    Αιτιολόγηση σχολίου / Εισήγησης
    Ο τομέας των Κατασκευών και του Δομημένου Περιβάλλοντος πρέπει να αξιολογηθεί τόσο βάσει της άμεσης οικονομικής του συνεισφοράς όσο και βάσει της εθνικής και συστημικής του σημασίας. Αποτελεί βασική υποδομή για τη στέγαση, τα δημόσια και ιδιωτικά έργα, τις μεταφορές, την ενεργειακή αναβάθμιση του κτιριακού αποθέματος, την τουριστική ανάπτυξη και σημαντικό μέρος των επενδύσεων της χώρας.
    Παράλληλα, παρουσιάζει εκτεταμένο πεδίο αξιοποίησης ΤΝ σε ολόκληρο τον κύκλο ζωής των έργων. Ενδεικτικές εφαρμογές περιλαμβάνουν BIM και digital twins, ανάλυση τεχνικών εγγράφων και σχεδίων, υποστήριξη ελέγχου κανονιστικής συμμόρφωσης, επιμετρήσεις, εκτίμηση κόστους και χρονοδιαγραμμάτων, computer vision για επιθεωρήσεις, εντοπισμό ελαττωμάτων, predictive maintenance και εφαρμογές ασφάλειας και υγείας.
    Πρόκειται επίσης για τομέα στον οποίο τα αποτελέσματα εφαρμογών ΤΝ μπορούν να επηρεάζουν τη δομική ασφάλεια, την ποιότητα των κατασκευών, την ασφάλεια και υγεία στην εργασία και την κανονιστική συμμόρφωση. Απαιτείται συνεπώς οργανωμένη υιοθέτηση, με ανθρώπινη εποπτεία, σαφή επαγγελματική ευθύνη και κατάλληλη διακυβέρνηση δεδομένων.
    Η συμπερίληψη του τομέα θα συνδέσει τη Στρατηγική με έναν βασικό τομέα υλοποίησης της οικονομικής, στεγαστικής, ενεργειακής και αναπτυξιακής πολιτικής της Δημοκρατίας.

  18. PUBLIC CONSULTATION SUBMISSION
    Cyprus National AI Strategy 2032
    Consolidated Response
    Submitted by: Cyprus Innovation Technologies (CyIT)
    Organisation: Not-for-profit technology think tank and enterprise association
    Consultation: Cyprus National AI Strategy 2032
    Consultation deadline: 31 August 2026.

    1. General Position
    CyIT welcomes the Cyprus National AI Strategy 2032 and its ambition to strengthen Cyprus’s competitiveness, public-sector modernisation, innovation capacity and responsible AI adoption. CyIT particularly welcomes the Strategy’s emphasis on research and innovation, public-private collaboration, entrepreneurship, skills, testbeds, sectoral adoption and a stronger national technology ecosystem.
    CyIT is a not-for-profit technology think tank bringing together expertise from technology, academia, finance, banking and professional services. Having evolved from Cyprus Blockchain Technologies into Cyprus Innovation Technologies, CyIT considers AI within the broader development — and increasing convergence — of emerging technologies.
    The comments below are offered constructively. CyIT considers the Strategy an important foundation and identifies a set of areas where greater strategic coherence, costed delivery detail and connection with the wider technology ecosystem would make it more effective and more implementable.
    2. Summary of Recommendations
    The following fifteen comments are set out in full, with section references, in Section 3 below.
    ● 1. Anchor the AI Strategy within an updated Digital Strategy. (Section 2.3.2)
    ● 2. Recognise technology convergence as a horizontal principle. (Sections 2.5, 3.5, 3.7, 3.8)
    ● 3. Consolidate governance into one coordinating body with clear, costed, time-bound mandates. (Section 3.3.1 and related governance provisions)
    ● 4. Extend digital readiness and legacy-system planning to systems — not data alone — modernisation, on a phased and costed timeline. (Sections 2.2.1, 2.2.2, 2.2.4, 3.2.5, 3.4.1, 3.7)
    ● 5. Build a genuine implementation and accountability architecture. (Sections 3.3.1, 3.5, 3.9)
    ● 6. Publish a costed national AI financing architecture. (Sections 3.3.1, 3.5, 3.7, 3.9, 3.10)
    ● 7. Recognise established, revenue-generating Cypriot firms as a distinct AI delivery and funding route. (Annex C)
    ● 8. Name a single approving authority and published criteria for use-case and moonshot selection. (Sections 1.4, 3.3.1, 3.4.2, 3.5)
    ● 9. Give the innovation ecosystem a structured, continuing implementation role. (Sections 3.3, 3.8, 4)
    ● 10. Design testbeds to accommodate converged, multi-technology solutions. (Sections 3.8, 3.8.5)
    ● 11. Extend private-sector support from pilots into funded production implementation. (Section 3.5)
    ● 12. Add local government as a distinct, resourced delivery layer. (Sections 3.4–3.5 and public-sector implementation generally)
    ● 13. Broaden AI-literacy programmes to cover emerging-technology convergence. (Section 3.6)
    ● 14. Extend the KPI framework to measure implementation and ecosystem outcomes. (Section 3.11)
    ● 15. Build in a periodic horizon-scanning and review mechanism. (Section 3.13)
    3. Detailed Comments and Recommendations
    Comment 1 — Anchor the AI Strategy within an updated Digital Strategy
    Relevant section(s): Section 2.3.2 (Alignment with Digital and Data Strategies); cross-cutting
    Issue: The Strategy is intended to guide Cyprus to 2032 but continues to rely partly on the National Digital Strategy 2020–2025. AI depends on wider digital foundations — data, connectivity, cybersecurity, digital identity, cloud/compute infrastructure, interoperability and digital public services — and increasingly interacts with blockchain/DLT, IoT, digital twins, robotics and automation.
    Recommendation: Update the overarching Digital Strategy for the period ahead and position the National AI Strategy clearly as a major implementation pillar within it, so AI and other emerging technologies develop within one coherent architecture rather than through separate technology silos.
    Comment 2 — Recognise technology convergence as a horizontal principle
    Relevant section(s): Sections 2.5, 3.5, 3.7, 3.8; Annexes C–D
    Issue: Although the Strategy references digital twins, robotics, autonomous systems and cybersecurity, it treats AI predominantly as a standalone technology. Cyprus already has capability and market experience in blockchain, fintech and distributed technologies that should be leveraged as AI develops, rather than treated as unrelated prior initiatives.
    Recommendation: Introduce technology convergence as a horizontal principle. Keep national programmes and use cases technology-neutral, but explicitly consider AI–blockchain/DLT convergence (trusted data and provenance, digital identity, tokenisation, smart contracts, supply chains, machine-to-machine transactions) where it improves outcomes.
    Comment 3 — Consolidate governance into one coordinating body with clear, time-bound mandates
    Relevant section(s): Section 3.3.1 and related governance provisions (pp.21–27); Sections 3.5, 3.9 (pp.33, 43); Annex A
    Issue: The Strategy creates at least ten standing bodies — the National AI Authority, Interministerial AI Council, National AI Taskforce, National AI Infrastructure Committee/Council, National Ethics and Values Committee, National AI Misinformation and Security Council, National AI Skills Observatory, Government Innovation Hub, AI Industrial Centre of Excellence and Cyprus AI Security and Certification Authority — plus AI Officers/Ambassadors and two designated resources in every ministry. No decision-rights map shows where one body’s mandate ends and another’s begins: the infrastructure body is named inconsistently as both “Council” and “Committee,” and Annex A refers to a “National AI Council” that is absent from the governance chapter itself. Neither the Deputy Ministry of Research, Innovation and Digital Policy (named as current implementation owner, p.8) nor the Department of Information Technology Services (not otherwise mentioned in the draft) is given a boundary against the new bodies. No body carries a term, review point or wind-down provision, even though the Strategy itself decommissions underperforming systems and programmes elsewhere (Annex B, Stage 5; §3.11.4).
    Recommendation: Consolidate to a single coordinating authority, with specialist functions (ethics, misinformation/security, infrastructure, skills) run as advisory panels sharing one secretariat rather than as standing bodies. Define that authority explicitly against the Deputy Ministry and DITS, stating what it does that they do not. Choose a lifespan: either a fixed term (five years is a reasonable default) with named successor arrangements for each function, or a broader “Modernisation and Innovation” mandate that outlasts the current AI technology cycle. Where a function can be carried by an existing institution, it should be, rather than creating a new standing body for it.
    Comment 4 — Extend digital readiness and legacy-system planning to systems — not data alone — modernisation, on a phased and costed timeline
    Relevant section(s): Sections 2.2.1, 2.2.2, 2.2.4, 3.2.5, 3.4.1, 3.7 (pp.10–11, 20–21)
    Issue: The Strategy correctly diagnoses fragmented, low-interoperability public-sector data and computing infrastructure, and acknowledges that “digital maturity varies across ministries and agencies” (§2.2.4), with some organisations lacking the capability to “identify, procure, and manage AI systems.” However, the stated prerequisite covers data modernisation only (§2.2.2); legacy systems, application modernisation and technical debt are not addressed, even though fragmented data is itself a symptom of an unintegrated application estate. The national data layer and National Intelligent Digital API Fabric (§3.2.5) — though called a prerequisite for the flagship portals — carry no owner, date or budget, and §3.4.1 commits only to “work towards” AI-first procurement principles “by 2032” with no interim milestones.
    Recommendation: Widen the stated prerequisite from data modernisation to systems-and-data modernisation, and assess the application estate alongside the data. Give each modernisation instrument, including the data layer and API Fabric, a named owner, budget and completion date. Require a published digital-readiness assessment for each ministry before AI systems are integrated into its legacy estate, and express at least one modernisation milestone as a gate on the adoption target so sequencing is visible and testable, rather than relying on the 2032 horizon alone.
    Comment 5 — Build a genuine implementation and accountability architecture
    Relevant section(s): Sections 3.3.1, 3.5, 3.9
    Issue: The Strategy sets out governance bodies, timelines and KPIs, but this falls short of delivery discipline. It does not yet translate the 2032 vision into programme-by-programme ownership, annual milestones, inter-programme dependencies, decision rights, a benefits-realisation methodology, or stated consequences when a programme falls behind. Without these elements, the 16 flagship programmes and 6 moonshots referenced in §3.5 risk remaining a strategic framework rather than a delivery programme.
    Recommendation: Require, for each moonshot programme once selected, a one-page delivery charter naming an accountable senior owner, annual (not only 2032) milestones, a dependency map against other programmes and infrastructure, a benefits-realisation plan with measurable indicators, and defined remedies for slippage. Review progress against these implementation commitments, not only against final 2032 targets.
    Comment 6 — Publish a costed national AI financing architecture
    Relevant section(s): Sections 3.3.1, 3.5, 3.7, 3.9, 3.10
    Issue: The Strategy commits repeatedly to expenditure without figures. Section 3.3.1 states only that “budget allocations will be aligned with the strategic performance goals agreed between the Ministry of Finance and the Deputy Ministry,” with no per-programme costing; Section 3.10 promises “multi-year investment with clear ROI tracking” without numbers; and Section 3.7 commits to a National AI Infrastructure described as a “strategic national asset” with no costed funding plan attached. This makes it difficult to assess whether the Strategy’s ambitions, including its 75% adoption target, are financially achievable.
    Recommendation: Publish an indicative national AI financing architecture for 2026–2032, itemising expected investment and the expected return or outcome metric by source — government funding, EU funding, private investment, R&D support, SME adoption subsidies, compute credits, procurement expenditure and venture/scale-up capital — and cross-reference it explicitly to the 75% adoption target so funding and ambition can be assessed together. Attach indicative cost ranges, funding sources, milestones and review dates to each major commitment, particularly the National AI Infrastructure.
    Comment 7 — Recognise established, revenue-generating Cypriot firms as a distinct AI delivery and funding route
    Relevant section(s): Annex C (pp.60–87, including p.73, p.86); Sections 3.3.1 (p.26), 3.3.2 (p.27), 5 (p.50)
    Issue: The Strategy builds two funding and delivery routes well — public-sector adoption (institutional AI strategies, delivery bodies, dated procurements) and the startup/spin-off pipeline (incubation, venture co-investment, university commercialisation). Established Cypriot firms past the startup stage but below corporate scale — already profitable and already holding sector knowledge in shipping, law, hospitality or finance — are the most likely source of exportable Cypriot AI products, yet they are named only once, in passing (“targeting the development of existing SMEs and MEs,” p.50). The nearest instrument, the AI Sovereign Investment Matching Fund, is shaped for equity rounds (25% pre-seed/seed, 75% Series A/B; conditions written for “any startup receiving government support,” p.86) and does not fit a profitable firm that is not raising a round.
    Recommendation: Name established AI-building/selling firms as a distinct route alongside the public-sector and startup routes, with its own logic from product development through capital to first customer and export. Clarify what “ME” means (align to the EU small mid-cap definition if intended) and ensure profitable firms not raising equity can access support. Prioritise funding for defined products with an identified buyer and a credible revenue path over studies and assessments, and consider models (e.g. the Israel Innovation Authority) where support is repaid from resulting revenue. Measure products reaching market, revenue and export revenue in Annex F, and give the AI Industrial Centre of Excellence a clear establishment date, budget and access criteria.
    Comment 8 — Name a single approving authority and published criteria for use-case and moonshot selection
    Relevant section(s): Sections 1.4, 3.3.1, 3.4.2, 3.5; Annexes B–C (Figures 5–12)
    Issue: Annex C lists “Recommended Use Cases, Moonshots and KPIs to be considered” for each of the eight priority sectors without making clear whether these are illustrative or committed. Section 3.5 states 16 flagship programmes will be assessed and narrowed to 6 moonshots by the National AI Authority “following stakeholder consultation” — without defining which stakeholders, what criteria, what weighting, or a decision date. At least three parallel, unreconciled approval pathways exist: the National AI Authority’s 16-to-6 selection; the Government Innovation Hub’s separate validation gate (§1.4.3); and ministries’ independent authority to identify and prioritise their own use cases (§3.3.1) through mandatory Applied AI Strategies. Annex B’s control gates add further checkpoints without specifying gate criteria or committee composition. The Strategy itself warns against “AI theatre” — “many experiments, little impact” (§1.4) — the likely outcome of naming aspirational use cases without a single approving authority.
    Recommendation: Name a single final approving authority for moonshot selection, publish selection criteria and their weighting, and fix a decision date for the 16-to-6 narrowing. Amend Annex B to name the approving body and pass/fail criteria for each control gate. Require ministry-level use cases selected outside the moonshot list to pass through the same Government Innovation Hub validation gate. Require multidisciplinary validation (public bodies, industry, academia, ecosystem) before major investment is committed, and review the use-case portfolio periodically.
    Comment 9 — Give the innovation ecosystem a structured, continuing implementation role
    Relevant section(s): Sections 3.3, 3.8, 4
    Issue: The Strategy’s emphasis on government–industry–academia collaboration is welcome, but effective implementation requires continuing engagement beyond consultation and strategy-development. Cyprus already has technology associations, not-for-profit organisations, innovation communities, professional bodies, startups and enterprises able to contribute market knowledge, identify use cases and support technology literacy.
    Recommendation: Provide a structured mechanism for continuing ecosystem participation during implementation, using existing ecosystem organisations rather than creating new public structures for functions they can already perform. CyIT would be willing to contribute within its areas of expertise and through its multidisciplinary membership.
    Comment 10 — Design testbeds to accommodate converged, multi-technology solutions
    Relevant section(s): Sections 3.8, 3.8.5; Annex D
    Issue: CyIT strongly supports the proposed testbeds, sandboxes and experimentation environments, but real-world innovation increasingly involves systems combining AI with other technologies; environments designed too narrowly around AI alone may limit experimentation and commercialisation.
    Recommendation: Design national testbeds to accommodate integrated solutions combining AI with blockchain/DLT, IoT, digital identity, digital twins, robotics, autonomous systems and cybersecurity where appropriate. Encourage a “pilot before scale” approach with measurable outcomes, and share non-confidential lessons from successful and unsuccessful pilots across the ecosystem.
    Comment 11 — Extend private-sector support from pilots into funded production implementation
    Relevant section(s): Section 3.5 (Supporting SMEs; NAICF Comply / AdoptNAICF)
    Issue: The private-sector support architecture is built almost entirely around SME adoption assistance, and specifically around preparatory stages: AdoptNAICF’s subsidy is gated behind NAICF Comply’s baseline AI Act governance requirement, and industry adoption is described as “not mandatory… however, highly recommended.” This funds compliance groundwork, studies, assessments and pilots, without a stated mechanism for funding the point at which a company integrates a system into production and runs it. The adoption challenge is also not limited to SMEs — larger Cyprus enterprises face similar implementation, integration, skills and infrastructure barriers, with no distinct support track outside the SME band.
    Recommendation: Restructure AdoptNAICF, or add a parallel instrument, to fund the ongoing running and integration costs of production AI implementations, not only studies and pilots. Introduce a distinct implementation-support track for enterprises outside the SME band, naming specific enablers — production-grade sandbox access, technical integration assistance, a delivery-support function — separate from NAICF Comply’s compliance guidance.
    Comment 12 — Add local government as a distinct, resourced delivery layer
    Relevant section(s): Sections 3.4–3.5 and public-sector implementation generally
    Issue: The Strategy focuses on central government and the eight priority economic sectors. Municipalities, however, deliver many services citizens experience directly — permits, waste management, planning, local infrastructure, traffic, environmental management and local-language services — and are not treated as a distinct delivery stream.
    Recommendation: Add local government as a named, distinct delivery stream within the public-sector programme, with its own use cases, resourcing pathway and digital-readiness assessment — paralleling the ministry-level readiness work in Comment 4 — rather than addressing municipalities only implicitly through national programmes.
    Comment 13 — Broaden AI-literacy programmes to cover emerging-technology convergence
    Relevant section(s): Section 3.6 (Talent, Skills and Workforce Transformation)
    Issue: CyIT strongly supports the emphasis on AI literacy and workforce transformation. However, executives, professionals, public officials and citizens increasingly need to understand AI within the wider technology environment — data, cybersecurity, cloud infrastructure, digital identity — with which it interacts.
    Recommendation: Add an emerging-technologies and technology-convergence dimension to AI-literacy programmes, particularly for policymakers, business leaders, professionals, SMEs and public-sector decision-makers, to support more informed technology selection and reduce both under-adoption and hype-driven adoption.
    Comment 14 — Extend the KPI framework to measure implementation and ecosystem outcomes
    Relevant section(s): Section 3.11; Annex F
    Issue: The Strategy contains extensive KPIs, but the ultimate test of a national technology strategy is successful implementation and a sustainable innovation ecosystem — whether pilots reach production, research is commercialised, SMEs and startups gain access to infrastructure and markets, and Cyprus develops internationally scalable solutions.
    Recommendation: Add measurable implementation and ecosystem indicators to the KPI framework alongside adoption metrics: pilot scale-up, industry–academia collaboration, SME/startup participation, private investment mobilised, commercialisation outcomes and internationally scalable solutions.
    Comment 15 — Build in a periodic horizon-scanning and review mechanism
    Relevant section(s): Section 3.13 (Risk Management, Resilience and Adaptation); cross-cutting
    Issue: A Strategy extending to 2032 must recognise that technologies, deployment models and significant use cases will emerge that cannot be fully predicted in 2026 — the pace of change in generative and agentic AI already demonstrates this.
    Recommendation: Include a periodic horizon-scanning and review mechanism covering material developments in AI and other emerging technologies (including their convergence), new use cases, risks, infrastructure requirements and international developments, drawing on government, academia, industry and the wider ecosystem, capable of informing adjustments to priorities and investment during implementation.
    4. Sector-Specific Observations
    Two further, narrower points from the underlying review drafts are recorded here for completeness, as they concern specific sector proposals rather than cross-cutting Strategy design.
    Comment 16 — Broaden the Financial Services / FinTech use-case programme
    Relevant section(s): Financial Services and Financial Technology priority sector
    Issue: The existing focus on AML, fraud detection, intelligent insurance, AI-augmented advisory and regulatory reporting is useful, but understates how quickly the sector is converging with tokenised assets, blockchain-based market infrastructure, digital identity, programmable payments, RegTech/SupTech and agentic financial services — an area where Cyprus already has deep professional, regulatory and market capability.
    Recommendation: Expand the financial-services use-case programme into an AI, FinTech and Digital Finance Innovation Track capable of considering convergent technology models.
    Comment 17 — Reconsider the role of blockchain in AIREG as part of a wider innovation programme
    Relevant section(s): Legal Services – AIREG
    Issue: CyIT welcomes blockchain’s appearance in the Strategy through the AIREG proposal, but no technology should be selected solely because it appears innovative, and blockchain should not be confined to a single registry use case without a feasibility assessment against alternative architectures.
    Recommendation: Reframe AIREG as one candidate use case within a broader, technology-neutral Trusted AI and Digital Provenance Programme, subject to a multidisciplinary feasibility and pilot process considering interoperability, data/metadata requirements, privacy, governance, digital identity, cybersecurity and evidentiary requirements — so that lessons generated can support other sectors.
    5. Standards and Regulatory Coherence
    CyIT recognises that implementation of the National AI Strategy will take place within the framework of the EU Artificial Intelligence Act, the national legislation being developed for its implementation, and the wider European regulatory environment.
    CyIT also recognises the important role of standards and of the Cyprus Organisation for Standardisation (CYS) in supporting interoperability, security, trustworthy AI and market access. These matters should be appropriately reflected in the final Strategy; CyIT does not consider it necessary in this submission to duplicate the detailed legal or standardisation analysis more appropriately addressed by competent institutions and specialist stakeholders.
    From CyIT’s perspective, the principal objective is to ensure that the regulatory and standards environment provides certainty and trust while remaining capable of supporting responsible experimentation, innovation, commercialisation and scaling.
    6. Conclusion
    Cyprus’s National AI Strategy 2032 sets an ambitious and largely well-founded direction, but its biggest risks are structural: it stacks new institutions, funding commitments and use-case selections without a single coordinating authority, a costed budget, or a clear decision-rights map, and it leans on the National Digital Strategy 2020–2025 rather than an updated digital foundation. Fixing these — one accountable governance body, a published financing architecture, and a clearer path from proposed use case to funded delivery — would do more for credibility than any single new programme.
    Beyond that, implementation readiness needs more attention than the draft currently gives it: legacy-system and digital-maturity gaps across ministries aren’t sequenced or costed, the moonshot/use-case approval process runs through at least three overlapping pathways, and established Cypriot firms sit in a funding gap between the startup and public-sector tracks the Strategy does address.
    Finally, the Strategy would be strengthened by treating AI as one part of a wider, converging technology landscape — recognising local government, the private sector beyond pilots, and the broader innovation ecosystem as ongoing implementation partners, broadening technology literacy accordingly, and building in periodic review so the Strategy can adapt as the technology and its use cases evolve through 2032.

  19. 1. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Section 3.8.1 and Annex D, Focus Area 5 (Next-Generation Wireless Telecommunications, printed p. 89); Section 2.2.1 (printed p. 9); Section 3.8.5 (National Testbeds, printed p. 41).
    Σχόλιο / Εισήγηση: Focus Area 5 should be given the same institutional treatment as the other focus areas: a named delivery mechanism, an associated testbed or experimentation facility, and at least one indicator in the Annex F framework. Specifically, add an advanced connectivity and network-AI testbed to the national testbed programme in §3.8.5, and state which body is responsible for the focus area.
    Αιτιολόγηση σχολίου / Εισήγησης: The six focus areas are presented as equivalent, but their institutional backing is not. Autonomous Systems is tied to a physical test park and to the maritime pillar; Healthcare to the National Health Data Repository; Security, Defence and Space to a dedicated Centre of Excellence. Next-Generation Wireless has three bullet points, no host, no facility and no indicator, and telecommunications does not appear among the eight priority sectors. Section 2.2.1 treats connectivity as an achieved condition (95.5% FTTH, 100% 5G coverage), which explains the omission but does not justify it: the Strategy elsewhere requires real-time AI services, edge deployment and national interoperability, all of which are network capabilities that do not exist today and will not arrive without directed investment. A research priority with no delivery mechanism attached will not attract funding and will not be measured.

  20. 1. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 3.8.1 and Annex D, Focus Area 5 (Next-Generation Wireless Telecommunications, printed p. 89); Section 2.2.1 (printed p. 9); Section 3.8.5 (National Testbeds, printed p. 41).
    Σχόλιο / Εισήγηση
    Focus Area 5 should be given the same institutional treatment as the other focus areas: a named delivery mechanism, an associated testbed or experimentation facility, and at least one indicator in the Annex F framework. Specifically, add an advanced connectivity and network-AI testbed to the national testbed programme in §3.8.5, and state which body is responsible for the focus area.
    Αιτιολόγηση σχολίου / Εισήγησης
    The six focus areas are presented as equivalent, but their institutional backing is not. Autonomous Systems is tied to a physical test park and to the maritime pillar; Healthcare to the National Health Data Repository; Security, Defence and Space to a dedicated Centre of Excellence. Next-Generation Wireless has three bullet points, no host, no facility and no indicator, and telecommunications does not appear among the eight priority sectors. Section 2.2.1 treats connectivity as an achieved condition (95.5% FTTH, 100% 5G coverage), which explains the omission but does not justify it: the Strategy elsewhere requires real-time AI services, edge deployment and national interoperability, all of which are network capabilities that do not exist today and will not arrive without directed investment. A research priority with no delivery mechanism attached will not attract funding and will not be measured.

    2. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 1.4.3 (printed p. 4); Section 3.3.1, Innovation and Development Bodies (printed p. 22); Section 3.3.1, National AI Industrial Centre of Excellence (printed p. 26); Section 3.4 (printed p. 31); Annex C, Government and Public Sector (printed p. 63); Section 2.2.3 (printed p. 10).
    Σχόλιο / Εισήγηση
    The Strategy should state the legal form and ownership model of each proposed Centre of Excellence, and should state the intended relationship between the new national Centres and the seven Centres of Excellence already operating in Cyprus, i.e whether the new Centres are to be hosted by, built upon, or established independently of them. A single consistent name should be adopted for each Centre throughout the document.
    Αιτιολόγηση σχολίου / Εισήγησης
    The Industrial Centre of Excellence is described in four incompatible ways: as an entity “dedicated to the private sector” (p. 4); as a body within the national governance structure (p. 22); as an entity that “reports to the National AI Authority” (p. 31); and as “a publicly supported private entity” (p. 63). These imply different procurement routes, different state aid treatment, different IP arrangements and different accountability lines. The question cannot be deferred to implementation, because the choice determines who may host or participate before any host is selected. Separately, §2.2.3 records that Cyprus already has seven Centres of Excellence, and no subsequent text connects them to the new bodies. Establishing national Centres alongside existing ones without stating the relationship risks precisely the duplication of public investment that §3.7 identifies as a structural weakness. The Centre is also named five different ways across the document, which should be corrected in the final text.

    3. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 3.3.1, National AI Industrial Centre of Excellence (printed p. 26); Annex C, Financial Services (printed p. 66); Section 3.9.6 (printed p. 43); Section 4.3, NAICF (printed p. 49); Annex A, EU AI Act (printed p. 53).
    Σχόλιο / Εισήγηση
    The Strategy should separate the development and assurance functions currently assigned to the Industrial Centre of Excellence. A body providing “development and engineering” across priority sectors should not also validate models against EU AI Act requirements before commercial deployment. The Strategy should further clarify the division of responsibility between the Centre, NAICF, the national certification registry, the “Cyprus AI Security & Certification Authority” named at p. 43, and the Competent Authorities already designated under the AI Act.
    Αιτιολόγηση σχολίου / Εισήγησης
    Page 26 tasks the Centre with resources, development and engineering; page 66 tasks the same Centre with validating models against EU AI Act requirements before commercial deployment and with producing compliance blueprints. An organisation cannot credibly assess systems it has helped build, and market participants that compete with the Centre’s engineering work will not accept its conformity judgements. The confusion is compounded by the number of assurance actors: NAICF, the registry, the Certification Authority (which appears once and does not appear in the governance structure at §3.3.) and the Communications Commissioner and Data Protection Commissioner, who hold the statutory role under the Act.

    4. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 3.3.1, National AI Cybersecurity Centre of Excellence (printed p. 26); Section 5, item 3 (printed p. 51); Section 3.3.1.6, National AI Misinformation and Security Council (printed p. 24); Section 4.2.1 (printed p. 49).
    Σχόλιο / Εισήγηση
    The two descriptions of the Cybersecurity Centre of Excellence should be reconciled, and the boundary between the Centre and the National AI Misinformation and Security Council should be drawn explicitly. The final text should also state on what terms international partners participate, in particular the ownership of intellectual property arising from jointly developed work and the treatment of results produced by Cypriot research institutions.
    Αιτιολόγηση σχολίου / Εισήγησης
    Page 26 describes a centre bringing together industry, academia and public institutions around frontier security research and practical standards. Page 51 describes a body operating “in partnership with leading global players” and developing “AI cyberwarfare professionals.” These are different institutions with different governance requirements, different security classifications and different funding models. The misinformation and disinformation remit at p. 51 also duplicates the mandate given to the Misinformation and Security Council at p. 24. On the partnership question, an anchor-partner model in which an international participant leads the technical work and domestic institutions supply personnel produces a centre that is located in Cyprus without building national capability(the outcome Objective 8 is intended to prevent!). Stating the IP and knowledge-transfer terms in the Strategy is what makes Objective 8 operative rather than aspirational.

    5. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 1.2 (printed p. 3); Section 1.4.3, “AI Centres of Excellence” (printed p. 4); Section 1.3 (printed p. 3); Section 3.3.1 (printed pp. 22, 26); Section 5, item 3 (printed p. 51); Annex C, Maritime (printed p. 83).
    Σχόλιο / Εισήγηση
    Reconcile the plural “AI Centres of Excellence dedicated to the private sector” at §1.4.3 with the two horizontal Centres actually defined at §3.3.1. Either state that sector-specific Centres will be established and identify which sectors, or amend §1.4.3 to describe a single horizontal Industrial Centre and drop the “dedicated to the private sector” characterisation, which does not match a body that also reports to the National AI Authority and supports ministries directly.
    The plural framing is unsupported. §1.2 (p. 3) describes CoEs as “industry-oriented”; §1.4.3 (p. 4) describes them as “dedicated to the private sector to accelerate use case adoption.” But the two actually defined are horizontal layers, not sector bodies, and the mapping onto the eight sectors is incoherent: The Industrial CoE is assigned to government (p. 63), financial services (p. 66), tourism (pp. 34, 73), legal services (p. 74), and at p. 51 to “GovTech, FinTech, ShipTech, tourism, and HealthTech.” That is one body for at least six of the eight sectors. The Cybersecurity CoE maps to no priority sector at all. It corresponds to Annex D Focus Area 4 (Security, Defence and Space), which is a research focus area and not a priority sector. Shipping and Maritime, the sector where Cyprus has its strongest global position, gets only a conditional: it “may be supported by a Centre of Excellence” (p. 83). Education, and Entrepreneurship and Innovation, get no CoE reference.
    Αιτιολόγηση σχολίου / Εισήγησης
    As drafted, one Industrial Centre of Excellence is expected to provide engineering, adoption support, governance guidance, compliance blueprints and sandbox validation across at least six of the eight priority sectors, each with distinct regulators, data regimes, professional bodies and technical requirements. No single organisation can hold credible domain depth across shipping, healthcare, legal services, tourism, finance and public administration simultaneously, and a body that attempts it will deliver generic advisory output — which is the “AI theatre” outcome the Strategy identifies as an execution risk at §1.4. Conversely, the Cybersecurity Centre is mapped to no priority sector, so the two Centres between them are simultaneously over-extended and unaligned to the sector structure the Strategy is organised around. Maritime is the clearest case: it is the sector with the strongest existing international position and the only one where a Centre is proposed conditionally.

    6. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 3.3.1, National AI Cybersecurity Centre of Excellence (printed p. 26); Section 1.1, Fundamental Principles (printed p. 2); Section 3.3.1.5 (printed p. 24); Section 3.9 and 3.13.3 (printed pp. 43, 46); Annex D, Focus Areas 4 and 6 (printed pp. 89–90); Section 5, item 3 (printed p. 51).
    Σχόλιο / Εισήγηση
    Rename National AI Cybersecurity Centre of Excellence to “National Centre of Excellence for Trustworthy and Secure AI”, and extend its mandate beyond cybersecurity to cover the full technical assurance of AI systems: adversarial robustness, model evaluation and benchmarking, red-teaming, bias and fairness auditing, explainability methods, privacy-preserving learning, and the development of national testing methodologies for high-risk systems under the EU AI Act. Cybersecurity remains within the mandate; it becomes one dimension of trustworthiness rather than the whole of it.
    Αιτιολόγηση σχολίου / Εισήγησης
    The Fundamental Principles at §1.1 commit Cyprus to security and resilience, fairness and non-discrimination, transparency and human oversight. Of these, only security is assigned to a body with technical capability. The National Ethics and Values Committee is advisory and described in a single sentence; NAICF addresses compliance and certification, which is a documentation function rather than a testing one. No body in the Strategy is responsible for determining whether a deployed system is actually robust, actually unbiased, or actually explainable. That is a technical question requiring laboratory capability, not an ethical or administrative one, and without it the AI Act conformity assessments the Strategy anticipates will rest on vendor self-declaration. Extending the Centre’s scope is also methodologically coherent: adversarial robustness testing, model evaluation, red-teaming and fairness auditing share techniques, tooling and expertise. Establishing a Centre that covers only the security subset and leaving the remainder unassigned would fragment a single technical discipline across bodies that do not exist. The narrower title also mismatches the mandate already given at p. 26, which includes securing AI systems themselves, which is an activity that is inseparable from evaluating them.

    7. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 2.2.2, final paragraph (printed p. 10); Section 1.5 (printed p. 6); Section 3.2.2 (printed p. 20); Section 5, items 1 and 6 (printed pp. 50, 52); Annex B, Control Gates 1 and 2 (printed pp. 58–59).
    Σχόλιο / Εισήγηση
    The characterisation of the National Data Policy and the National Data Governance Framework as a prerequisite rather than a parallel activity is correct and should be retained. It should also be made operative: state a target publication date for both instruments, sequence the implementation timeline at §1.5 and the immediate steps at §5 against that date, and add an explicit data-readiness condition at Annex B Control Gate 1 or 2, so that a use case cannot pass the gate without demonstrating that the data it depends on is governed, documented and lawfully available under the national framework.
    Αιτιολόγηση σχολίου / Εισήγησης
    Section 2.2.2 correctly identifies the sequencing that most national AI programmes get wrong. As drafted, however, the Strategy states the dependency in Chapter 2 and does not observe it thereafter. No delivery date is given for either instrument, while §1.5 places infrastructure deployment and pilot launches at 6 to 12 months and §5 commits to launching procurements for six transformational solutions within eight months. If the data framework is genuinely a prerequisite, then those milestones are conditional on a deliverable with no date, and the timeline cannot be relied upon. If it is not a prerequisite, the paragraph at §2.2.2 should be amended. Attaching the requirement to a control gate is the mechanism that makes the stated principle binding, since it is at the gate that a project either has governed data or does not.

    8. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 3.7 and 3.7.2 (printed pp. 38–39); Section 3.3.1.4, National AI Infrastructure Committee (printed p. 24).
    Σχόλιο / Εισήγηση
    The Strategy should specify the composition of the National AI Infrastructure Committee, including representation from universities and research organisations, and should clarify the intended treatment of existing publicly funded institutional research computing, whether it is to be consolidated, federated, or left in place with coordinated access. My opinion is that any infrastructure already in place should remain so, and there should be coordinated access to all, if needed and possible. The HPC at UCy has a research and Educational purpose, which cannot be ignored and cancelled. The body is called a Council at §3.3.1 and a Committee at §3.3.1.4; one term should be used.
    Αιτιολόγηση σχολίου / Εισήγησης
    Section 3.7.2 states that the National AI Infrastructure should not belong to “any individual ministry, university, research organisation, or company,” and §3.7 opens by characterising existing institutional resources as fragmented and duplicative. Read together, these imply a consolidation of resources that were competitively won and are currently committed to funded research programmes with contractual obligations to European funders. Consolidation and federation are both defensible, but they have very different consequences for existing projects, and the Strategy does not say which is intended. Section 3.7.2 also assigns oversight to “an appropriate governance framework representing government, academia, research organisations, and industry,” while §3.3.1.4 defines the Committee’s functions without defining its membership. Since that body will set annual compute priorities, its composition determines whether the stated representation is real.

    9. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 5, item 2 (printed p. 50); Section 4.4, Incentive Mechanisms and AI ERC Bridge (printed p. 50); Annex C, Legal Services (printed p. 75); Annex F (printed p. 93).
    Σχόλιο / Εισήγηση
    The National AI Research Fund and the AI ERC Bridge should be given an administering body, an indicative multi-annual allocation and a first-call date. The Strategy should state the role of the Research and Innovation Foundation in the national AI research portfolio.
    Αιτιολόγηση σχολίου / Εισήγησης
    The National AI Research Fund is stated as a single line with an ambition: placing Cyprus among the top fifteen European nations for AI research excellence. However, there is no administering body, no allocation and no timeline. The AI ERC Bridge is a sub-bullet. Neither appears in the Annex F measurement framework. The Research and Innovation Foundation, which currently administers competitive national research funding, is named once in 101 pages, in the Legal Services annex, as a co-funder of compliance auditing rather than of research. Six research focus areas and a research excellence target cannot be delivered by instruments that have no owner, and the omission of the existing national funding agency from a national research strategy will be read either as an oversight or as a signal of institutional change. Either reading warrants clarification in the final text.

    10. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 1.4.2 and 1.4.10 (printed pp. 4, 6); Section 3.2.1 (printed p. 20); Annex A, Digital, Cybersecurity and Data Frameworks (printed p. 54); Annex C, Healthcare (printed p. 68) and Maritime (printed p. 83).
    Σχόλιο / Εισήγηση
    Add the Data Governance Act, the Data Act, the Open Data Directive and the European Health Data Space Regulation to the instruments listed at §1.4.10, and convert the single bullet at §3.2.1 into a stated participation plan: which Common European Data Spaces Cyprus intends to join, in what order, which national body acts as counterpart in each, whether Cyprus will designate data intermediation and data altruism organisations under the DGA and which authority will register and supervise them, and how the national Trusted Maritime Data Space and the GHS health sandbox will connect to their European counterparts rather than operate as isolated national constructs.
    Αιτιολόγηση σχολίου / Εισήγησης
    The Strategy positions Cyprus as a trusted jurisdiction and a bridge between the EU and neighbouring regions, and Objective 6 commits to interoperable data foundations. Neither claim is supported by the current text, which refers to European data spaces only in general terms and to the EHDS only as a source of principles. The Data Governance Act, which is the legal instrument that makes cross-border data sharing operable and which imposes designation obligations on Member States, is not mentioned anywhere in the document. Sectoral data spaces built to national specification and later retrofitted to European ones cost substantially more than spaces built to the European reference architecture from the outset, and the Strategy elsewhere identifies avoidance of retrofitting as a design principle under “data by design.” Naming the instruments and the intended accession sequence is a drafting change with no cost that materially strengthens the interoperability commitment.

    11. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 1.4.2, fifth bullet (printed p. 4); Section 1.4.6 (printed p. 5); Section 3.2.1 (printed p. 20); Section 3.2.2 (printed p. 20); Section 3.7 and 3.7.2 (printed pp. 38–39).
    Σχόλιο / Εισήγηση
    Separate the compute commitment from the data commitment. The fifth bullet of §1.4.2 should be limited to data infrastructure — secure processing environments, sectoral data spaces, and the API fabric — with compute capacity moved to §1.4.6, where it is already addressed. The Strategy should also resolve whether the national data architecture is federated (§3.2.1) or consolidated onto a shared platform (§1.4.2, §3.7.2), since these are incompatible.
    Αιτιολόγηση σχολίου / Εισήγησης
    Data and compute are governed by different legal regimes and require different institutional arrangements. Compute governance concerns capacity allocation, procurement and energy. Data governance concerns lawful basis, controllership, sectoral custodianship and the accountability of named data owners that §3.2.2 establishes. Describing them as one platform implies that whoever operates the national compute becomes the custodian of the national datasets placed on it, which would displace the data-owner model set out in §3.2.2 and create GDPR controllership questions for health, tax and justice data that the Strategy does not address. The conflation also produces a direct contradiction: §3.2.1 commits to a federated architecture that avoids unnecessary centralisation of sensitive information, while §1.4.2 commits to replacing scattered resources with a single shared platform. Both statements cannot be implemented.

    12. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 1.5, success metrics (printed p. 6); Section 2.5.2 and 2.5.5 (printed pp. 16–17); Section 3.6.2 (printed p. 37); Annex C, Education and Human Capital Development — NASO and FutureAI CY (printed pp. 79–81); Annex F.
    Σχόλιο / Εισήγηση
    Add a tertiary capacity component to Objective 5 and to the Education pillar: a multi-annual programme of publicly funded additional undergraduate and postgraduate places in computer science, data science and artificial intelligence at the state universities, with the corresponding academic posts and laboratory capacity, and a funded doctoral scheme in the six research focus areas of Annex D. Enrolment and completion in these programmes should be a tracked indicator in Annex F, and NASO’s forecasting should feed directly into the allocation of places rather than only into reporting. The Strategy should also separate the labour-demand figure at §2.5.2 from the workforce-supply figure at §2.5.5, since they are currently the same number describing different things.
    Αιτιολόγηση σχολίου / Εισήγησης
    The Strategy sets a target of approximately 3,000 AI professionals by 2032 and then names no mechanism capable of producing one. CALF addresses ages 6 to 18 and produces no graduates within the Strategy’s horizon. FutureAI CY delivers micro-credentials of 5 to 15 ECTS to working adults, against 240 ECTS for a bachelor’s degree; these are valuable for AI literacy and workforce augmentation but do not produce AI engineers or data scientists, which the target explicitly names. NASO measures the gap and the talent-attraction measures at §3.6.5 compete for a scarce international supply, but neither adds domestic capacity. The absence of the state universities from the supply plan is a structural gap: they are the only institutions in Cyprus that can produce degree-qualified AI engineers, and expanding their capacity requires funded places and academic posts committed years ahead of the graduation date. A target set for 2032 with no undergraduate intake decision before 2027 cannot be met by domestic supply, which leaves attraction as the only remaining route. This instrument contradicts the sovereignty that is a goal.

    13. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
    Section 2.2.3, second paragraph (printed p. 10); Section 1.4.7 (printed p. 5); Section 2.5.3 (printed p. 16); Section 3.8 (printed pp. 40–42); Annex D, Focus Area 6 — Foundational AI Research (printed pp. 89–90).
    Σχόλιο / Εισήγηση
    Amend the second paragraph of §2.2.3 so that the observation about research translation is retained without implying that research which does not produce an operational solution has failed. Suggested reframing:” links between research and deployment remain uneven, and mechanisms for translating applicable research into operational solutions require strengthening, alongside sustained support for foundational research, which produces the methods, tools and trained researchers on which applied work depends and whose returns are realised over longer horizons.” Correspondingly, the prioritisation language at §1.4.7 and §2.5.3 should be balanced so that it does not subordinate the foundational research that Annex D Focus Area 6 identifies as a national priority, and the National AI Research Fund at §5 should carry a stated allocation for foundational work.
    Αιτιολόγηση σχολίου / Εισήγησης
    The observation that translation is uneven is fair and worth keeping. The framing, however, treats every research output that does not become an operational solution as a shortfall, which is not how research systems function: foundational work produces methods, evaluation techniques, tooling and trained researchers whose value is realised through later applied work, often by other groups and after long intervals. A national system that funds only research with an identified operational endpoint imports its foundations from elsewhere and forfeits the capacity to evaluate what it imports, which sits directly against Objective 8 on sovereign capability, since sovereignty in AI means the ability to understand and assess systems, not only to deploy them. The Strategy is also inconsistent on this point. Annex D names Foundational AI Research as one of six national focus areas, listing privacy-preserving learning, resource-efficient AI and robust anomaly detection, while §1.4.7 and §2.5.3 direct prioritisation toward applied and impact-oriented research. A focus area that is named as a priority in an annex and deprioritised in the funding language of the main text will not be funded. Doctoral training is the concrete case: it is the principal mechanism by which foundational research produces the skilled workforce the Strategy targets at §2.5.5, and it appears in neither the research nor the talent provisions.

  21. CONTRIBUTION TO THE PUBLIC CONSULTATION ON THE DRAFT NATIONAL AI STRATEGY 2032 OF THE REPUBLIC OF CYPRUS

    Submitted by Uncommon People Consulting, Sociedad Limitada (Spain), ESB16469710. http://www.uncommonpeople.eu. 27 August 2026.

    COVER NOTE

    1. We congratulate the National AI Taskforce and the Chief Scientist for Research, Innovation and Technology on a draft Strategy of unusual scope, and on its willingness to state the constraints as plainly as the ambitions. Four features are particularly welcome: the human-centred principle that runs through the document; the age-banded architecture of the Cyprus AI Literacy Framework; the teacher-mediated design of the Ethical Pedagogical Validation Layer; and, above all, the education pillar’s declared ambition, that Cyprus become a leading European hub for AI in education by 2032.

    2. This contribution is authored by an independent strategic practice that has studied seventeen national AI-in-education programmes on three continents, and the Cypriot education landscape in depth. It is filed in the public interest. It seeks no contract for the delivery work it proposes, and no exception and no preference of any kind; Comment 12 states plainly what we would and would not accept, and on what terms.

    3. This contribution concentrates on a single question: deliverability. We comment on the education pillar alone. Page 4 names a shortage of specialised AI skills among the Strategy’s structural weaknesses, and page 6 counts 3,000 or more AI professionals among its success metrics, beside modernised shipping, maritime, healthcare, tourism and professional services. The other pillars are where those people work; this is the pillar they come from. The education chapter itself warns that, without coordination, fragmented pilots will produce low impact and unequal access; every comment below is offered to strengthen the pillar’s path from framework to classroom. Twelve comments follow in the requested format, in four groups matching the four questions on which delivery depends. Who delivers: comments 1 to 3. What is taught, and how safely: comments 4 to 6. Where trust is built and systems are proven: comments 7 and 8. And how the work is measured, funded, and kept honest: comments 9 to 12.

    4. Where this contribution points to a provision of the draft Strategy, it gives the section, page, or figure, so the reference can be checked in minutes. Statements about other countries rest on the accompanying annex, where each programme carries named, dated sources and estimates are identified as estimates. No factual claim in this contribution asks to be taken on trust. We have also read the whole record of this consultation as it stood on the day of filing, and where another contributor reached shared ground first, the relevant comment says so and seconds them: convergence among independent contributors is evidence in its own right, and the final text is easiest to strengthen where the record already agrees.

    5. We wish to be plain about what we offer, and in what spirit. We have undertaken substantial preparatory work: benchmarking across seventeen national programmes on three continents; a study of the Cypriot education landscape in depth; and a complete, costed delivery design for a pillar of this shape, phased over five years, with governance, phase gates that can stop the work as well as advance it, a risk register, an evaluation framework, partner-selection criteria and the strategy for applying them, and a financial model reconciled to the Union instruments named in our tenth comment, showing how every component would be paid for. The philanthropic and private participation our eleventh comment contemplates is mapped within that model. We stand ready to present that work in full to the National AI Taskforce and the competent ministries, on request, without charge and without condition. And should the Taskforce or the ministries wish to discuss any part of it, we are at their disposal: a request suffices. We add one thing in candour: a contribution of this scope inevitably shows how we work, and we are content to be judged by it.

    6. All of this work is offered in support of, and never in substitution for, the work of the National AI Taskforce and the competent ministries, whose frameworks the comments below take as their foundation.

    7. One further conviction informs every comment below: implementation should build Cypriot capability rather than import around it. This consultation itself demonstrates the depth of the island’s ecosystem, with a ministry, statutory bodies, research figures, educators, technology firms, and AI vendors raising their hands in these very pages. Comment 12 turns that conviction into a mechanism the Republic can hold anyone to, including ourselves.

    COMMENT 1: A NAMED DELIVERY VEHICLE FOR THE EDUCATION PILLAR

    ARTICLE AND SECTION

    Annex C, Education and Human Capital Development (pages 77 to 81); Section 3.5, priority sector 6.

    COMMENT / SUGGESTION

    The education pillar defines three excellent national instruments (CALF, EPVL, NASO) and a governance architecture for oversight, but names no organisation whose daily work is delivery: recruiting and training the teacher corps, producing and maintaining classroom materials, running pilots, and reporting results. We respectfully suggest that the final Strategy recognise a dedicated, independent, non-profit delivery vehicle for the education pillar, established as a foundation under Cyprus law, constituted on five principles: (a) government seats on its board alongside academia, the teaching profession, parents, and industry; (b) any private founders holding a structural minority, with an independent Cypriot chair; (c) statutory anchoring so the programme survives electoral cycles; (d) published audited annual accounts and independently evaluated results; and (e) recognition of the vehicle against published qualification criteria, so that any candidate, whatever its provenance, is measured to the same public standard.

    JUSTIFICATION

    The two national programmes most relevant to Cyprus by scale and ambition both run on precisely this model, and both appear in the literature the National AI Taskforce itself reviewed. Estonia’s AI Leap operates as a public-private partnership through a dedicated delivery organisation, with its pilot year supported by an investment of approximately EUR 4 million co-funded in equal parts by the Ministry of Education and Research and private partners; teachers were trained before students entered, and the programme launched nationally for upper-secondary grades in September 2025 with some 20,000 students and 3,000 teachers, expanding further in September 2026. Greece delivers national education programmes through the Onassis Foundation while the Ministry retains full ownership of policy and curriculum. The counter-examples are equally instructive: where national initiatives were run as procurement projects without a dedicated institution, notably the Republic of Korea’s AI Digital Textbook programme and the Los Angeles Unified School District’s device programme, they consumed public and private budgets measured in the hundreds of millions to billions of dollars and were reversed or abandoned within two years. The consistent lesson of these cases is that an institution, rather than a project, is what carries an eight-year target credibly. The pillar’s own stated goal, replacing fragmented pilots with a scaled, trusted national approach, is an organisational outcome and requires an organisation.

    One further consideration strengthens the case: the draft establishes a considerable number of new institutional bodies, and none of them carries a stated budget or headcount. A delivery vehicle so recognised, arriving with funded capacity of its own, would be the exception that proves deliverability, an institution able to act from its first day.

    One caution now on the record deserves adoption alongside the recommendation itself. A contributor writing as chair of a statutory national committee has observed that a strategy document can establish advisory, assurance and control-gate arrangements, but should not imply that any body holds licensing, enforcement or adjudicative powers the law has not conferred. We agree without reservation, and the recommendation is built for exactly that boundary: recognition in the Strategy does the work a strategy can do, naming the function and the published criteria, while powers, duties and permanence are conferred where alone they can be conferred, in law. The caution states, from institutional experience, exactly why point (c) asks for statutory anchoring: an eight-year programme needs both layers, and neither substitutes for the other.

    A contribution to this consultation argues that the draft creates too many new bodies for an administration of this size, and sets a test for any that are created: demonstrate the capability gap, show why an existing institution cannot fill it, name the resources that will sustain it, and state how its contribution will be measured. We think that is the right test, and we would have this recommendation judged against it. The gap is the one this comment opens with. The reason an existing institution cannot fill it is the reason the international record gives: a ministry running this as a project, rather than an institution running it as its daily work, is what failed in Korea and in Los Angeles. The resources are private and philanthropic rather than a further call on the public payroll, so the vehicle adds delivery capacity without adding public administration, which is the concern the test exists to serve. The measurement is points (d) and (e) above. We would rather meet that test than argue with it.

    Should the Taskforce find drafted wording useful, one sentence in the pillar’s implementation section would serve: ‘Delivery of this pillar will be supported by a dedicated, independent, non-profit delivery vehicle, with government and public-interest seats on its board, any private founders in a structural minority under an independent Cypriot chair, published audited accounts and independently evaluated results, recognised against published qualification criteria open to any candidate, and anchored in law.’

    COMMENT 2: MAKING THE CERTIFIED-EDUCATORS COMMITMENT MEASURABLE

    ARTICLE AND SECTION

    Annex C, Education and Human Capital Development; Figure 10 (certified educators as an expected deliverable and KPI).

    COMMENT / SUGGESTION

    Figure 10 correctly lists certified educators among the pillar’s expected deliverables, and it is the only place in the pillar where that deliverable is named: the phrase appears nowhere in the chapter’s text. The chapter specifies no training volumes, no sequencing, and no certification body relationship beyond the committee structure. We recommend that the final Strategy commit to: (a) a numerical teacher-training target with dates, sized against the roughly 17,300 teachers serving at all levels of the Republic’s education system (17,298 in the Education Survey 2023/2024 of the Statistical Service of the Republic of Cyprus, the latest published); (b) an explicit sequencing rule that a first tranche of no fewer than 1,500 teachers is trained and certified before any classroom deployment of AI tools; (c) annual recertification so the corps keeps pace with the technology; and (d) that the deliverable be carried in the pillar’s text and not in a graphic alone, so that it survives the figure reconciliation proposed in our ninth comment.

    JUSTIFICATION

    Teacher readiness is the single strongest predictor of success or failure across national programmes. Estonia trained its teacher cohort before students entered the programme, and in its first year 94% of participating teachers used AI in their work, with 63% incorporating it into their teaching. The Republic of Korea deployed AI Digital Textbooks to classrooms in March 2025 ahead of teacher readiness; classroom adoption halved within a single term, from 37% to 19% of schools, and in August 2025 the National Assembly revoked the books’ textbook status, after a public commitment of roughly USD 850 million and private publisher investment reported at some KRW 800 billion, roughly USD 570 million, with teacher and parent unpreparedness cited among the leading causes. Finland’s Elements of AI and the United Kingdom’s National Centre for Computing Education both demonstrate that a certified educator pipeline is buildable at national scale within one to two school years when it is planned first. A deliverable that appears only in an infographic is also a deliverable that escapes text search, and therefore the one most likely to be lost in an editorial pass or overlooked by the ministries implementing the pillar; writing it into the chapter costs a sentence and secures the commitment. Attaching a numerical target here is precisely the kind of strengthening this consultation invites. The record of this consultation now carries an educator’s proposal for a national teacher training and certification programme built around a levelled Cyprus AI Educator Certificate, kept current as the technology moves, and, from a second contributor, a call for a structured national professional development programme for teachers and academic staff carrying measurable participation and competency targets. We second both with enthusiasm, and they complete one another: the certificate gives the commitment its instrument, the competency targets give it a standard, and the volumes and dates above give both their scale, their sequence and their cadence. Adopted together, they would leave Figure 10’s certified-educators deliverable with a name, a standard, a volume, an order and a renewal cycle: everything a deliverable needs in order to be delivered.

    COMMENT 3: PILOT BEFORE SCALE, WITH PUBLISHED GATES

    ARTICLE AND SECTION

    Annex C, Education and Human Capital Development (implementation); Annex B, AI Use Case Lifecycle and Control Gates.

    COMMENT / SUGGESTION

    The draft’s Annex B establishes a disciplined lifecycle with control gates for AI use cases across government. We suggest the education pillar apply that same discipline to itself, explicitly: (a) a named pilot phase of 25 to 30 schools selected by published criteria across urban, rural, and disadvantaged catchments; (b) a published review at the end of the pilot year, with pass criteria defined in advance; and (c) explicit authority at each gate to stop, extend, or redesign before national scale-up. The pilot’s evaluation should be independent and its results published regardless of outcome.

    JUSTIFICATION

    The most expensive education-technology failures of the last decade share one feature: scale preceded evidence. The Los Angeles Unified School District committed approximately USD 1.3 billion to a district-wide device deployment before its curriculum was complete; the programme collapsed within two years and ended in litigation. The Republic of Korea scaled nationally in a single step, with the outcome described in the previous comment. By contrast, the United Arab Emirates piloted, embedded, and then scaled, and its programme endures; Estonia began with two grade cohorts and published its adoption data, favourable and unfavourable alike. Cyprus’s size is a strategic advantage here: a 25 to 30 school pilot is a meaningful sample of the entire system, something no large country can say, and the draft Strategy elsewhere recognises exactly this rapid-validation advantage in its research annex. The failure mode has a name in the Strategy itself. Page 4 lists among its structural weaknesses a risk of “AI theatre”, many experiments and little impact, and page 63 answers that warning for the Government pillar with an explicit discipline of outcome-led selection focused on measurable results. The education pillar is given no equivalent, and published gates are how that discipline reaches the classroom. Publishing the gates in advance also protects the Strategy itself: pausing a pilot against published criteria reads as prudence, while pausing a national rollout is a far harder story for any government to tell. The record of this consultation asks for the same discipline from several directions, entry and exit criteria for pilots and clearer tests for the passage from pilot to production among them; what this comment adds is the education pillar’s own version: the named pilot, the published criteria, the independent evaluation, and the authority to stop.

    COMMENT 4: EMBED AI LITERACY RATHER THAN ADD IT, AND PILOT THE CALF RUBRICS WITH TEACHERS

    ARTICLE AND SECTION

    Section 3.6.1 (AI literacy and awareness); Annex C (Cyprus AI Literacy Framework).

    COMMENT / SUGGESTION

    We warmly endorse CALF’s four developmental bands and their alignment with the Key Competences for Lifelong Learning and the UNESCO and OECD competency frameworks. Three suggestions to strengthen implementation: (a) pilot the classroom-ready assessment rubrics jointly with the first teacher-training wave, so the instrument and its users are validated together rather than sequentially; (b) state explicitly that CALF outcomes are delivered by embedding within existing subjects (mathematics, science, languages, design and technology) rather than through new standalone timetable hours; and (c) specify accessible-by-design outcomes in the rubrics, so that learners who use assistive technology are inside the framework rather than exempted from it.

    JUSTIFICATION

    Joint piloting halves the calendar and surfaces the real failure modes: a rubric that works in a specification but not in a classroom is discovered only when trained teachers use it with real students. On embedding: the United Arab Emirates reached national coverage in months by placing AI content inside existing subjects, where there was nothing to displace and therefore nothing to negotiate. Reforms built on new timetable hours face the opposite arithmetic: an hour must be taken from something, and whatever it is taken from has a constituency. The Strategy states the embedding principle in mandatory terms twice, on consecutive pages. Page 25: “AI initiatives shall be embedded within existing policy, operational and accountability structures and shall not be treated as standalone or experimental activities.” Page 26 repeats it in slightly different words. Both provisions address how ministries adopt AI rather than how a curriculum is built, but the logic is identical, and the education pillar does not apply it. Embedding also reaches every learner rather than only those who elect a new subject, which serves the pillar’s own inclusion commitments. One further point belongs with the rubrics. On page 77 the pillar states that all learners, including vulnerable groups, should benefit from inclusive, accessible design, and on page 79 it gives the Pedagogical and AI Safety Committee, the body that maintains the CALF rubrics, the further task of validating accessibility checks. CALF’s outcomes, however, are banded by age alone, so that committee is asked to validate accessibility against a framework which does not express it. Specifying accessible-by-design outcomes within the existing bands would give the commitment its instrument, and would place the learners who use assistive technology, whether captioning, text-to-speech, reading support or communication aids, inside the framework rather than beside it.

    COMMENT 5: EPVL: SPECIFY THE SAFETY INSTRUMENT BEFORE ANY CLASSROOM DEPLOYMENT

    ARTICLE AND SECTION

    Annex C, Education and Human Capital Development (EPVL, including the provision that it “will be specified in a separate technical and pedagogical annex”).

    COMMENT / SUGGESTION

    The Ethical Pedagogical Validation Layer is, in our reading, the pillar’s most important safety commitment: teacher-mediated, age-aware, culturally respectful, and auditable. Because the draft defers its specification to a future annex, we would ask the final Strategy to add four commitments, three of sequence and one of content: (a) the EPVL technical and pedagogical annex is published for consultation before any classroom deployment of AI tools; (b) EPVL validation is operational for a tool before that tool reaches students, without exception; (c) EPVL is piloted alongside the first teacher-training wave so its audit and mediation workflows are shaped by practising teachers; and (d) the annex names child-specific protections explicitly: exclusion of engagement-maximising, addictive, manipulative and deceptive design patterns, prohibition of commercial profiling of minors’ data, age-appropriate design standards for every interface a student touches, and confirmation that no deployed system infers emotions from biometric data, which Union law already prohibits in education institutions.

    JUSTIFICATION

    Deploying classroom AI before its validation layer exists would invert the pillar’s own logic and create avoidable exposure under Union law: AI systems in education fall within the high-risk regime of the Artificial Intelligence Act, whose education obligations apply from 2 December 2027 following Regulation (EU) 2026/1744. An operational EPVL is very close to a ready-made conformity and human-oversight architecture for that regime; sequenced correctly, Cyprus would arrive at the compliance deadline with an instrument other member states will still be designing. Sequenced incorrectly, the Republic would be retrofitting safety onto systems already in front of children, which is the costliest order of operations in both money and trust. The fourth ask closes a gap that runs wider than this pillar. The draft’s only provision touching minors is EPVL’s check on age appropriateness, which asks whether material suits a child, not whether a system is built to exploit one; addictive design, the commercial profiling of minors’ data, and age-appropriate design standards appear nowhere in the document, though children are the Strategy’s youngest and least defended users. The EPVL annex is the natural home for those protections, and a single annex can close the gap for the entire document. The record of this consultation shows other contributors pressing the same protections, and we second them gladly; what this comment adds is the sequence and the home: the protections named inside the EPVL annex, and the annex operational before any tool reaches a student. Should the Taskforce wish to draft the protections now, one paragraph would serve, the last of its four requirements restating a prohibition already in force rather than proposing a new one: ‘Every AI system deployed in classrooms shall exclude engagement-maximising, addictive, manipulative and deceptive design patterns; shall not profile minors for commercial purposes nor permit reuse of their data for such profiling; shall conform to age-appropriate design standards for every interface a student touches; and shall not infer emotions from biometric data, which Article 5 of the Artificial Intelligence Act already prohibits in education institutions. EPVL validation verifies each requirement, per tool, before deployment; its findings are auditable; and a teacher, parent or student has a named route to report a suspected breach after deployment.’

    COMMENT 6: PAIR AI LITERACY WITH ROBOTICS: THE MIND AND THE BODY OF THE MACHINE

    ARTICLE AND SECTION

    Annex C, Education and Human Capital Development; Annex D, Focus Area 2 (Autonomous Systems); Section 3.8.5 (National Testbeds); Section 5 (Autonomous Systems Park).

    COMMENT / SUGGESTION

    Robotics is present in the draft’s research agenda (Annex D names robotic perception, human-robot interaction, and swarm systems) and in its innovation infrastructure (the planned Autonomous Systems Park), yet it is absent from the education chapter. We suggest that the final Strategy: (a) pair AI literacy with robotics and physical computing as one curriculum strand, built on programmable microcontroller hardware of the micro:bit or Arduino class, at tens of euros per learner rather than thousands per room, so that learners meet both the reasoning of the machine and its physical expression, and so that the strand reaches every school on operating budgets without waiting on a capital programme; (b) connect the education pillar explicitly to the Autonomous Systems Park, giving schools a national venue for applied robotics, and provide that, where learners are present, the “clearly defined operational, legal, safety, and ethical boundaries” the draft already promises for its testbeds gain a pedagogical limb: teacher-mediated access and human-in-the-loop supervision of the kind EPVL establishes for classroom AI, extended to physical systems, since the safety case for a child beside an autonomous vehicle is not the safety case for a child at a screen; and (c) establish a national student robotics competition structure, with regional leagues feeding an annual final.

    JUSTIFICATION

    The case is practical before it is cultural, and inexpensive before it is either. Physical computing is not an enrichment of AI literacy but its completion: a learner who has only ever seen a model’s answer on a screen has not met the point at which code acquires consequences, and that is precisely the point at which autonomous systems are engineered. Screen-based literacy alone also loses the learners who learn by building, among them many of the engineers a national strategy most needs, and a programmable board costing tens of euros gives exactly those learners their way in. The deployment arithmetic follows: a strand built on hardware at that price is a recurring operating line rather than a capital programme, so it can begin in the pilot schools and reach the network without waiting for buildings. The engagement evidence is international and durable, with competition circuits such as FIRST and the World Robot Olympiad sustaining participation at national scale across income levels. The draft itself supplies the remaining pieces of the argument. Annex D observes that Cyprus’s scale supports rapid validation cycles and practical pilots, and names human-robot interaction “to ensure safe, trusted collaboration” among its research priorities: the education pillar is where that research meets its youngest subjects. The Autonomous Systems Park is a capital investment in drones, autonomous vehicles and robotics whose return depends on people who can build, operate and maintain them, and a park without a domestic pipeline staffs itself by import. That pipeline can only begin in schools and runs on a decade’s lead time: the cohort that meets its first microcontroller in gymnasio is the cohort that staffs the Park in the 2030s. A generation that has built and programmed machines by the age of eighteen is the surest route to the Strategy’s own target of 3,000 or more AI professionals, and the cheapest. And there is a cultural claim waiting to be made: the first imagined humanoid machine in world literature, Talos, guarded the shores of Crete, an island of the same sea. Pairing the mind and the body of the machine in Cypriot classrooms is not an import but a homecoming.

    COMMENT 7: A PUBLIC VENUE WHERE THE STRATEGY MEETS ITS PUBLIC

    ARTICLE AND SECTION

    Annex C, Education and Human Capital Development (national ambition and trust); Section 3.5 (public-private collaboration principle).

    COMMENT / SUGGESTION

    We propose the addition of a public engagement dimension to the education pillar: a flagship public venue for AI and robotics learning, open to families and visitors as well as schools. Without specifying any site, scale, or design, the venue’s uses can be named now, because each answers a commitment the pillar has already made: for schools, curriculum-linked visit programmes that extend the classroom rather than interrupt it; for teachers, a permanent home for certification days, training cohorts, and the shared practice a dispersed profession otherwise never develops; for families, exhibitions and community days where parents watch their children programme a moving machine; for adults, short reskilling courses run with the training institutions the Republic already funds; for students, a national stage for the robotics leagues proposed in our sixth comment; and for the Republic, a place where the Strategy can be seen: the venue that hosts the delegations, the student finals, and the annual summit its international ambitions deserve. Curriculum reform is, by its nature, invisible to the public that funds it; a place with those uses converts an administrative programme into a national story, and public trust, which the pillar itself identifies as a condition of success, is built far faster in person than on paper.

    JUSTIFICATION

    The European science-centre evidence is long-standing and quantified. Estonia’s AHHAA centre in Tartu attracts in the order of a quarter of a million visitors a year (246,434 in 2023, as published by the centre) in a city of roughly 97,000 inhabitants, and centres of its class typically recover a substantial share of operating costs through admissions, programmes, and events, limiting the long-term call on public operating budgets. The capital is a separate question with a separate answer: a venue of this kind is the sort of investment Union cohesion instruments exist to co-finance, alongside the co-funded partnerships the pillar’s own public-private collaboration principle already contemplates.

    The obvious follow-up deserves a direct answer too: why not use what exists. The island’s universities and research centres are designed for researchers and enrolled students, and their opening hours, safety regimes and layouts follow from that purpose; none is built for a class of thirty on a Tuesday morning or a family on a Saturday afternoon. A public venue is a different instrument, and the two are complements rather than alternatives: the venue draws its content, its demonstrations and much of its expertise from those institutions, and gives them a public face they were never built to provide.

    A venue of this kind also carries a value the pillar’s text does not yet name: international visibility. A national centre hosting ministerial delegations, international student competitions, and an annual regional summit places the Republic’s education initiative in front of the world’s press and policy community on a recurring calendar, coverage of a kind small states rarely obtain and never at this cost. It also gives the pillar’s other instruments a home: teacher certification days, CALF assessment pilots, student competitions, and public demonstrations of exactly the human-centred AI the Strategy promises. Neutral ground may be its quietest value: the one floor where more than one provider’s systems can stand side by side, under the same roof and the same rules, compared in public rather than chosen in private. Several contributions to this consultation warn against dependence on any single provider; a place built for plurality is that warning heeded in architecture, and it changes the Republic’s position in every negotiation that follows, because a state that can compare is a customer every provider must court. Nor need that plurality be left to hope: the timing favours the Republic for reasons set out later in this contribution, and the preparatory work behind it addresses how such participation would be assembled and on what safeguards; the detail travels with the rest of our work, on request.

    No square metre or site need be specified in the Strategy; recognising the venue dimension as part of the pillar is sufficient to enable it. If the Taskforce wishes to make that recognition operative, one sentence would do so: tasking the pillar’s implementation phase with a feasibility assessment of such a venue, drawing on the European science-centre model, converts recognition into a datable, ownable action while committing the Republic to nothing beyond the study itself.

    COMMENT 8: SCOPE A NATIONAL REGULATORY SANDBOX TO EDUCATION

    ARTICLE AND SECTION

    Section 3, subsection headed “Enabling Responsible Experimentation”; Section 5, Immediate Steps (industry sandboxes programme); Annex B.

    COMMENT / SUGGESTION

    We would encourage the Taskforce to name education explicitly as a domain of the planned national sandbox architecture. Under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, every member state must have at least one national AI regulatory sandbox operational by 2 August 2027, and the same instrument applies the high-risk regime to education systems from 2 December 2027. Scoping a sandbox to education converts a compliance obligation into the pillar’s own testing infrastructure: classroom AI tools, the EPVL validation layer, and teacher-facing systems could each be validated under supervision before deployment.

    JUSTIFICATION

    Education combines the Strategy’s most sensitive user population, children, with its hardest Union-law deadline, which argues for the most structured testing environment the state can offer. A named education sandbox would also be an early-mover position in the Union: few member states have scoped their sandbox obligations by sector, and the first to run classroom AI through a supervised sandbox would be well placed to shape the practice others follow. The draft’s Annex B control-gate lifecycle supplies a ready-made evaluation framework; the sandbox gives those gates a home.

    COMMENT 9: RECONCILING THE STRATEGY’S TARGETS, DATES AND FIGURES BEFORE ADOPTION

    ARTICLE AND SECTION

    Annex C pages 77 to 81 (education pillar, including Figure 10); Figures 5, 7 and 11 (pages 64, 71 and 85); Section 3.5, Healthcare (pages 33 to 34) with Annex C page 68; Section 1.5; Section 2.2.1.

    COMMENT / SUGGESTION

    In the spirit of strengthening the final text, we note the following for the editorial pass. These notes begin in the education pillar and end in a pattern that affects the document as a whole.

    (a) The education pillar’s 2032 adoption target reads 75% in the priority-sector summary and in the pillar table on page 81, but 50% in the Figure 10 infographic printed immediately beneath that table on the same page; the final text may wish to reconcile the two. A related reconciliation would strengthen the whole document: 75% appears as a target in three different scopes, industry adoption by 2030 (Section 5, Immediate Steps, under “Accelerating Adoption and Industry Readiness”, page 51), overall adoption by 2032 in the Government pillar (cited as in line with the Digital Decade target, whose own form is 75% of enterprises by 2030), and education and labour by 2032 in Annex C. Stating each pillar’s target once, with its own scope and date, would remove any doubt about what is promised, to whom, by when.

    (b) The pillar’s baseline, 13% adoption across education and labour, carries no stated source and no metric definition: it is not specified as a share of teachers, students, schools, workers, or enterprises. The document itself shows the form the figure needs: the enterprise-adoption baseline of 9.27% in Section 2.2.1 is defined, given a trend (an annual progression of 17.3% since 2024) and set against a comparator (the EU average of 19.95%), and giving the 13% the same three-part treatment would let the pillar’s headline target be measured with the same confidence. The subsection headed “Strategic objectives and 2032 target” would also benefit from stating the target as a number.

    (c) Page 79 twice renders the Deputy Ministry’s name as the Deputy Ministry of Digital Policy, Research and Innovation; the official form, used elsewhere in the Strategy including on page 80 of the same annex, is the Deputy Ministry of Research, Innovation and Digital Policy.

    (d) The Figure 10 variance does not appear to be isolated. Because the pillar infographics are images, their content escapes text-based checking, and reading them figure by figure against the surrounding text shows the same pattern in three further pillars: Figure 5 (Government, page 64) gives 75% adoption “by 2030”, the 40% reduction in citizen waiting times “by 2030”, and intelligent governance “by 2035”, where the pillar text gives 2032 for all three; Figure 7 (Healthcare, page 71) gives virtual human twins “by 2035”, agreeing with the pillar’s deliverables table on page 70, while the pillar’s text on page 68 gives 2032 for the same deliverable; and Figure 11 (Shipping, page 85) gives the Intelligent Maritime Orchestrator ambition and its capability KPI “by 2035”, where the pillar text gives 2032. We would respectfully suggest a figure-by-figure reconciliation pass before adoption, so that the final Strategy states each of its targets once, identically, in text and graphic alike.

    (e) The same reconciliation is needed where the body text dates its own deliverables. On page 33, the Secure National Health Data Repository initiative states that its governance arrangements “will be elaborated in the dedicated AI healthcare strategy, to be developed by December 2027”; on page 34, the same chapter closes by stating that “a full-scale AI healthcare strategy is recommended for development by 2028”; and the Annex C healthcare pillar repeats the 2028 form on page 68. As drafted, the same instrument appears to carry two dates and two statuses, a commitment on one page and a recommendation on the next; and because a named initiative expressly defers its governance detail to that strategy, the strategy’s date and status deserve to be stated once. If two distinct documents are intended, saying so expressly would serve the same end.

    (f) In Section 1.5, the three relative implementation windows (0 to 8, 6 to 12, and 12 to 24 months) carry no stated start date, and two of the seven success metrics are prefaced “Recommended”; anchoring the windows to a date and firming the verbs would strengthen the scorecard against which the Strategy will be measured.

    (g) The certified-educators deliverable would benefit from the numerical targets suggested in our second comment.

    JUSTIFICATION

    These notes are offered with genuine appreciation for the scale of drafting the Taskforce has undertaken; documents of this breadth inevitably accumulate small variances, and this one carries remarkably few in its text. Other contributors have noticed some of the same variances: one asks that the final text distinguish committed targets from strategic ambitions and scenario estimates, which is the point made at (f) above approached from another direction, and another asks that every indicator carry a definition, baseline, data source and named owner, which is the general form of the point made at (b) above; all three strengthen the case for one reconciliation pass before adoption rather than corrections piecemeal. The graphics deserve particular attention for exactly that reason: because figure text cannot be searched, variances there are the likeliest to survive into the adopted Strategy, and those noted above were found only by reading every pillar figure against its surrounding text. The stakes are practical rather than editorial: points (d) and (e) in particular bear on measurement rather than wording, and may merit the attention of those who own the targets as well as of the editorial pass. Foundational numbers and dates are inherited downstream by procurement documents, KPI dashboards, and ministry work plans, and no pillar can be delivered against a target the document states two different ways. All of this is easiest to align while the text is still open.

    COMMENT 10: A FUNDING ARCHITECTURE FOR THE EDUCATION PILLAR

    ARTICLE AND SECTION

    Section 3.10 (sustainability and economic model); Section 1.4.9; Annex C (Education and Human Capital Development).

    COMMENT / SUGGESTION

    We recommend that the final Strategy attach a funding architecture to the education pillar: at minimum, a mapping of the Union instruments available to it, and ideally an indicative envelope. The instruments are substantial and already aligned with the pillar’s components: Erasmus+ Teacher Academies for the certified-educator pipeline; Digital Europe Programme skills actions for advanced digital capability; Horizon Europe, including the Teaming instrument that Cyprus has used successfully before, for the research dimension; and the Thalia 2021-2027 cohesion programme for physical infrastructure.

    JUSTIFICATION

    Every expected deliverable of the education pillar depends on sustained funding, yet the pillar carries no financial reference of any kind, a silence it shares with the Government, Healthcare, and Tourism pillars, in a document whose only programme-level financial figures are the EUR 5,000 threshold of the AI Judge capability and the EUR 1 million per round of the investment-matching fund. The education pillar is where that silence costs most, because its deliverables are recurring rather than one-off: teachers must be trained and recertified every year, content maintained, and evaluations published for as long as the pillar lives. The benchmark evidence should encourage rather than daunt: Estonia runs its pilot year on approximately EUR 4 million, co-funded in equal parts by the state and private partners, achieved by sequencing teachers first and adapting existing tools rather than commissioning new platforms. Naming the available instruments costs the Republic nothing, signals seriousness to the Union bodies that co-fund such work, and answers in advance the first question every implementing ministry will ask: who pays. Other contributions to this consultation have remarked on the same silence; this comment differs in offering the remedy, the instruments named and the mapping made.

    COMMENT 11: WELCOMING CO-FUNDED DELIVERY PARTNERSHIPS

    ARTICLE AND SECTION

    Annex C (Education and Human Capital Development); Section 3.5 (public-private collaboration principle).

    COMMENT / SUGGESTION

    Finally, we invite the Taskforce to consider one enabling sentence in the education pillar: ‘The Republic welcomes co-funded delivery partnerships, including philanthropic participation, for the implementation of this pillar, under public governance safeguards and the compliance framework this Strategy establishes.’ Should the Taskforce wish to make that welcome operative, a second sentence would do so: ‘The implementation phase will convene prospective co-funders, philanthropic and corporate, under the same safeguards.’ Together they give interest a named public doorway and the Republic the convening seat.

    JUSTIFICATION

    The draft already embraces public-private collaboration as an adoption principle; this suggestion simply extends that principle explicitly to the education pillar, where the international precedents are strongest. Estonia’s programme is co-funded in equal parts by the state and private partners through a dedicated delivery organisation; Greece’s most significant national education programmes are delivered with philanthropic institutions under ministry policy control. Demand for such partnerships will not need to be manufactured: the Union’s classroom-AI obligations take effect on 2 December 2027, and providers will need demonstrably compliant national deployments inside an EU jurisdiction before that date. An explicit welcome in the final text gives any future partner, and the Republic itself, a clear and orderly doorway, with the state holding the keys; and a pillar that admits more than one partner under identical terms and independent evaluation keeps the Republic permanently in the stronger position. One further observation belongs here, because the record of this consultation will be read by more than its addressees. The architecture the draft already contains, public governance, independent evaluation, control gates that can stop work, and published results, is precisely the architecture serious philanthropy requires before it commits; the draft has, perhaps without intending it, already written the assurance side of a co-funding agreement. What is missing is only the invitation. Foundations do not volunteer into silence. An explicit welcome in the adopted text is how both kinds of participation become proposable in Cyprus: the mission philanthropy that funds national education delivery in Greece, and the private co-funding that carries half of Estonia’s. We would discuss either kind with the Republic gladly, whenever asked.

    COMMENT 12: OPEN PROCUREMENT FOR THE PILLAR’S RECURRING DELIVERY WORK, AND A DECLARATION OF INTEREST

    ARTICLE AND SECTION

    Section 3.3.2, Control Framework (approval gates before procurement; approved and certified delivery and implementation partners); Annex C, Education and Human Capital Development; Annex F (national KPIs and measurement framework).

    COMMENT / SUGGESTION

    We recommend that the final Strategy commit the education pillar’s recurring delivery work, systems integration, content production, training logistics, and platform operations, to open, competitive procurement, and that Annex F carry an indicator reporting annually the share of that contract value awarded to Cyprus-resident suppliers. A declaration of interest belongs beside that recommendation, so that it binds its proposer first. We are an independent practice, not a candidate delivery vehicle, and we hold no interest in any body that is, as at the date of this contribution; should that change, we would say so. We have prepared, at our own cost, a complete implementation plan of the kind these comments describe, and we would wish to see such a programme built, by whichever body the Republic’s published criteria select. That plan is offered to the Republic without charge and without condition. We seek no exception and no preference: if we were ever engaged in connection with this pillar, whether by the Republic or by a body funding the work, that engagement would come either through open competition or on ordinary commercial terms openly stated, on the same footing as any other candidate. The division of labour we advocate binds us first: the recurring delivery work this comment commits to open procurement, the systems, the content, the logistics and the operations, belongs to the market, Cypriot firms foremost, and we would take no part in it; designing how an institution is to work and operating it are different trades, and we do only the first, save for one bridge between them which the list below names and bounds. Our own part in this pillar is strategy, and if the Republic or a funder ever sought that work from us it would be strategic work of the kinds this contribution has already required: assembling and sequencing the applications to the Union instruments named in our tenth comment, with the case-building each one needs; keeping the design current as Ministry data arrives, as Union law moves and as the international evidence changes; transitional programme coordination until the delivery body’s own leadership is in post, which is that bridge: work someone must do before the institution exists to do it itself, ending on an appointment we do not make; the design of that body’s operating model and of the performance framework it reports against; and supporting the Republic in convening the international participation described above, the Republic holding the convening seat throughout. None of that is delivery work and none of it is the delivery role itself, and any of it would be commercially negotiated on the terms just stated. We would not evaluate what we designed: the independent evaluation our third comment asks for must be independent of us too. We state this plainly rather than leave it to be discovered.

    JUSTIFICATION

    The draft returns to small and medium-sized enterprises throughout, more than twenty times across its chapters, and the commitment is unmistakable. What the text does not yet carry is the machinery that would deliver it: lot design, reserved participation, and an indicator tracking the share of contract value that remains with Cyprus-resident firms. The education pillar is a natural place to begin, because its delivery work recurs by nature, and spend that is procured openly circulates through the island’s own technology sector year after year, strengthening the ecosystem the Strategy sets out to grow. We note with agreement that other contributions to this consultation have proposed kindred machinery: reserved procurement lanes for Cyprus-resident SMEs, with express indicators for the AI contract value awarded to them. The placement is this comment’s addition: an indicator carried in Annex F, which the record elsewhere also asks to hold outcome indicators of other kinds. One such contributor, a Cypriot vendor, stated its own interest as plainly as we state ours; we simply stand on the other side of the same disclosure, a Spanish practice proposing an indicator that counts a category which cannot include us. A mechanism urged both by those it would include and by those it cannot include arrives corroborated on the only ground that matters. The declaration above is offered in the same spirit: we would rather be held to it than believed. A practice that asks for open procurement, states its own interest plainly, and accepts for itself the criteria it proposes for others, gives the Republic something it can check.

    ANNEX: WHAT SEVENTEEN NATIONAL PROGRAMMES TEACH

    This annex summarises publicly documented outcomes of national AI-in-education and related digital-education programmes reviewed for this contribution: Croatia, Estonia, Finland, France, Greece, Malta, the United Kingdom, the United Arab Emirates, Qatar, Saudi Arabia, Israel, Singapore, South Korea, Japan, China, India, and the United States. All figures are as publicly reported at the date of filing; sources are named for each programme, and where a figure is an estimate the text says so.

    A. DELIVERY MODELS THAT WORKED, AND WHY THEY WORKED

    Estonia. The AI Leap programme launched nationally on 1 September 2025 for upper-secondary grades, with some 20,000 students and 3,000 teachers, and expands in September 2026 to vocational schools and new cohorts, adding roughly 38,000 further students. It operates as a public-private partnership through a dedicated delivery organisation; the pilot year is supported by approximately EUR 4 million co-funded equally by the Ministry of Education and Research and private partners including Telia, Skaala, and the Smart Future Fund. Teachers were trained first, and the effect shows in the first-year results: 94% of participating teachers used AI in their work and 63% incorporated it into their teaching. Estonia also publishes its adoption data candidly, including the less flattering weekly-use figures, and adjusts accordingly; that habit of published honesty is itself part of the model. A country of comparable size to Cyprus, spending in the low single millions, is now the reference point for an entire continent. Sources: Ministry of Education and Research announcement of the AI Leap programme (hm.ee, February 2025); TI-Hüpe programme site and first-year results (tihupe.ee, 2026), which also name the co-funding partners.

    Greece. National-scale education delivery in partnership with the Onassis Foundation, with the Ministry retaining full ownership of policy and curriculum; separately, a national agreement bringing AI tools into schools. The significance of the model is what it removes: no procurement friction, no political ownership battles, and delivery capacity that does not depend on the electoral cycle, all while the state keeps every decision that belongs to the state. Sources: Ministry of Education of Greece; Onassis Foundation.

    United Arab Emirates. AI content embedded within existing subjects, enabling nationwide coverage within months rather than years, scaled after piloting, and still operating and deepening today across all school grades. The demonstration that speed and durability are compatible when the sequencing is right. Sources: UAE Ministry of Education announcements.

    Finland. Elements of AI, a university-led open course, made AI literacy a mass phenomenon, reaching, as publicly reported, more than a million learners across dozens of countries from a standing start, and proving that well-designed content, not expensive platforms, is the scarce ingredient. Sources: University of Helsinki and MinnaLearn, Elements of AI enrolment reporting (elementsofai.com).

    United Kingdom. The National Centre for Computing Education built a national teacher-certification pipeline for computing through a network of hubs and subject-knowledge certificates, upskilling teachers by the tens of thousands: the closest operational template in Europe for a certified-educators KPI with real numbers attached. Sources: National Centre for Computing Education impact reporting (teachcomputing.org); Department for Education.

    Singapore. Sustained, incremental integration of AI into schooling under successive national masterplans, with teacher capability treated openly as the binding constraint and adaptive learning systems introduced only as that capability matured. Sources: Ministry of Education of Singapore.

    B. CAUTIONARY EVIDENCE: HOW NATIONAL PROGRAMMES FAIL

    South Korea. The chronology deserves attention because it is recent and complete. The AI Digital Textbook plan was announced in June 2023; 76 textbook titles were approved in September 2024; the books entered classrooms with the school year in March 2025, ahead of teacher readiness and without a gated pilot. Classroom adoption fell from 37% of schools in the first semester to 19% in the second, and in early August 2025 the National Assembly amended the law to strip the books of textbook status, reclassifying them as supplementary materials and ending their funding mandate. The public commitment is reported at roughly USD 850 million, participating publishers invested a reported KRW 800 billion, roughly USD 570 million, and the 2026 digital-education budget was subsequently cut to roughly one sixth of its prior level. One of the most digitally advanced school systems on earth, with resources few nations can match, lost its programme not to technology but to sequence. Sources: Korea Herald, “South Korea pulls plug on AI textbooks” (August 2025); Rest of World, “South Korea’s AI textbooks fail after rushed rollout” (2025); Ministry of Education of Korea announcements and National Assembly proceedings, 2023 to 2025.

    United States (Los Angeles). A district-wide device programme of approximately USD 1.3 billion, launched in 2013 before its curriculum was complete, collapsed within two years amid procurement failures and a December 2014 federal investigation, and Pearson settled with the district for USD 6.45 million in October 2015. A single school district outspent most national education budgets, and its experience is now part of the evidence every later programme can draw on. Sources: contemporaneous United States reporting, 2013 to 2015; the federal investigation of December 2014 and the Pearson settlement of October 2015 are matters of public record.

    China and Japan. Large-scale national pushes illustrate both the productivity potential of AI in learning analytics and the governance questions raised by classroom surveillance applications; the human-centred boundary the draft Strategy sets is the correct one, and worth defending explicitly as deployments scale. Sources: national policy documents; OECD reviews.

    The warning these cases carry is specific, not general. Korea’s reversal is barely a year old. Both failures occurred in systems with far greater resources than any small state commands, and in both cases the missing elements were exactly those the draft’s education pillar currently leaves unspecified: teacher volumes, pilot gates, a delivery institution, and a funding architecture. The comments in this contribution ask for nothing more than the insertion of those elements while the text is still open, because every one of them has already been paid for, expensively, by someone else.

    C. INVESTMENT CONTEXT

    Israel, Qatar, Saudi Arabia, France, India, Malta. Each is investing systematically in AI skills through national strategies, dedicated institutes, or school programmes, confirming that the education-AI race is global and that windows of distinction close quickly. Croatia’s BrAIn programme, listed above and reviewed on the same basis, run by the CARNET network under the Ministry of Science, Education and Youth with EUR 16 million of funding, 85% of it from the European Social Fund Plus, brings AI curricula into schools as elective and extracurricular subjects from the 2025/2026 school year: the nearest EU signal that first-mover room inside the Union is finite. Sources: CARNET BrAIn project documentation (carnet.hr); national AI strategies; EU monitoring.

    D. THE PATTERN, IN ONE PARAGRAPH

    Across seventeen programmes the pattern is stable: initiatives succeed when teachers precede students, pilots precede scale, content precedes hardware, delivery has an institution rather than a project office, and evaluation is independent and published. They fail, at costs measured in the hundreds of millions to billions, when any of those orders is reversed. Cyprus’s draft Strategy already contains the principles; the comments above ask only that the final text bind them to the education pillar with numbers, sequence, and a named delivery function, qualified against published criteria.

  22. Σχόλια Διεύθυνσης Νοσηλευτικών Υπηρεσιών Υπουργείου Υγείας

    Η Διεύθυνση Νοσηλευτικών Υπηρεσιών του Υπουργείου Υγείας αναγνωρίζει ότι η Τεχνητή Νοημοσύνη (ΤΝ) αναμένεται να διαδραματίσει καθοριστικό ρόλο και στον ψηφιακό μετασχηματισμό του Συστήματος Υγείας, συμβάλλοντας στη βελτίωση της ποιότητας των παρεχόμενων υπηρεσιών. Ως εκ τούτου είναι σημαντικό στην Εθνική Στρατηγική Τεχνητής Νοημοσύνης να συμπεριληφθούν ή και να αναφέρονται τα ακόλουθα:

    1. Αναγκαιότητα ανάπτυξης ενός ολοκληρωμένου πλαισίου ενίσχυσης των δεξιοτήτων του ανθρώπινου δυναμικού στον τομέα της Τεχνητής Νοημοσύνης στην Υγεία. Η επιτυχής ενσωμάτωση εφαρμογών ΤΝ προϋποθέτει την κατάλληλη εκπαίδευση και συνεχή επιμόρφωση των επαγγελματιών υγείας, των διοικητικών στελεχών και του λοιπού προσωπικού, ώστε να μπορούν να αξιοποιούν τις νέες τεχνολογίες με ασφάλεια, υπευθυνότητα και αποτελεσματικότητα.

    2. Η αξιοποίηση της Τεχνητής Νοημοσύνης έχει αποκλειστικά υποστηρικτικό χαρακτήρα και δεν υποκαθιστά σε καμία περίπτωση την επιστημονική κρίση, την επαγγελματική ευθύνη και τη λήψη αποφάσεων από τους επαγγελματίες υγείας.

    3. Η αξιοποίηση εφαρμογών Τεχνητής Νοημοσύνης στον τομέα της Υγείας πραγματοποιείται στο πλαίσιο αυστηρών προδιαγραφών προστασίας των προσωπικών δεδομένων και ιδιαίτερα των δεδομένων υγείας. Απαιτείται η εφαρμογή κατάλληλων μηχανισμών ασφάλειας, διαφάνειας και ελέγχου όσον αφορά τη συλλογή, επεξεργασία, αποθήκευση και αξιοποίηση των δεδομένων από συστήματα ΤΝ.

    4. Ενεργός συμμετοχή των επαγγελματιών υγείας και ιδιαίτερα των νοσηλευτών και μαιών στον σχεδιασμό και την εφαρμογή λύσεων ΤΝ.
    Η ανάπτυξη και εισαγωγή εφαρμογών ΤΝ στο Σύστημα Υγείας πραγματοποιείται με ουσιαστική συμμετοχή των επαγγελματιών που θα τις χρησιμοποιούν στην καθημερινή πρακτική. Ειδικότερα, η συμμετοχή νοσηλευτών και μαιών είναι σημαντική, δεδομένου του άμεσου και συνεχούς ρόλου τους στην παροχή φροντίδας και στην επικοινωνία με τους ασθενείς.

    5. Αξιοποίηση της ΤΝ για μείωση του διοικητικού φόρτου των επαγγελματιών υγείας. Ιδιαίτερη έμφαση θα μπορούσε να δοθεί σε εφαρμογές που αυτοματοποιούν ή υποστηρίζουν διοικητικές και επαναλαμβανόμενες εργασίες, χωρίς να επηρεάζουν την ασφάλεια της φροντίδας, με στόχο την εξοικονόμηση χρόνου και τη δυνατότητα των επαγγελματιών υγείας να αφιερώνουν περισσότερο χρόνο στην άμεση φροντίδα των ασθενών.

  23. Closing comments from the German Medical Institute.

    Offer of contribution
    We offer the following without charge:
    • Our clinical AI deployment lifecycle and local validation protocol, including the chest X-ray evaluation methodology and the Greek-language reference-standard problem and how we addressed it, as a candidate template for a national validation protocol.
    • Participation in the drafting of the dedicated AI healthcare strategy and in the design of the healthcare regulatory sandbox, including the regulatory classification and conformity assessment questions raised in Comments 1 and 2.
    • Our membership of the European Network of AI-Powered Advanced Screening Centres as a channel for exchange between the national programme and current European deployment practice.

    If the Republic procures validation, conformity or advisory services in this area, we would tender for that work on the same terms as any other provider, and we distinguish that clearly from the contributions offered above.

    We thank the National AI Taskforce and the Chief Scientist for the substantial document, and for a consultation process that invites this kind of detail. Our comments are offered in support of the Strategy’s direction and its ambition for Cyprus to be a credible and fast route to the European market for trustworthy health AI. We would welcome the opportunity to discuss any of them.

  24. Comment 8 of 8 from the German Medical Institute

    Comment 8: Define the workforce target and accredit clinical AI training through the professional bodies

    Article / paragraph: Section 3.5, Priority Sector 3 (“By 2032, Cyprus aims for 50% of its medical workforce to be trained in AI-enabled practices”); Section 3.6.2 (Advanced and Sector-Specific Skills); Annex C, Healthcare and Life Sciences; Annex C, Education and Human Capital Development (FutureAI CY); Annex F.

    Comment / Suggestion: Amend the workforce provisions to: (a) define “medical workforce” so that the 50% target is extended beyond physicians to the wider clinical workforce, including medical physicists, radiographers, nurses and laboratory scientists; (b) accredit clinical AI training as continuing professional development through the Cyprus Medical Association and the relevant professional bodies, so it carries professional recognition; and (c) structure it in three tiers: general clinical AI literacy for the whole workforce, a smaller cohort with deployment and evaluation competence, and a designated clinical AI lead in each institution.

    Justification: As drafted the target cannot be measured, because the term “medical workforce” is not fully defined and because “trained in AI-enabled practices” has no stated competence standard.
    The AI Act requires meaningful human oversight of high-risk systems, but this only applies when the overseeing clinician is competent to disagree with the system. They need to know its failure modes, to recognise when a case is outside its validated distribution, and to have the confidence to override it. That is a different competence from knowing how to use a tool, and it is what local validation, drift monitoring and post-deployment surveillance all require. A national programme that trains 50% of the workforce to use AI tools, without producing the smaller cohort that can evaluate and govern them, will have satisfied the target and not the underlying requirement.
    We would add that the clinical workforce in AI-enabled care is not only physicians. In our own deployments, medical physicists and radiographers carry much of the evaluation and quality assurance work.

  25. Comment 7 of 8 from the German Medical Institute

    Comment 7: Specify a health-designated secure processing environment within the National AI Infrastructure

    Article / paragraph: Section 3.7 (Infrastructure, Compute and Digital Sovereignty), particularly 3.7.2, 3.7.3 and 3.7.4; Section 3.7.5 (Integration with EuroHPC and the European AI Factory Ecosystem); Annex C, Healthcare and Life Sciences.

    Comment / Suggestion: State that the National AI Infrastructure will include a health-designated secure processing environment, operating on the European Health Data Space model where data does not leave the environment and only results are exported. The infrastructure should be suitably sized for medical imaging, and available to hospitals, researchers and validation programmes under the Data Access Committee governance the Strategy already describes.

    Justification: Health data cannot be served by a general-purpose allocation policy alone: it requires environments where the access controls, audit trails, residency guarantees and export restrictions are fundamental properties of the infrastructure. Sovereignty for health data is not a question of scale, but rather in which environment the data sits and who governs access.

  26. Comment 6 of 8 from the German Medical Institute

    Comment 6: Make interoperable digitalisation a dated obligation for all providers contracted to the General Healthcare System

    Article / paragraph: Section 3.2.4 (Data by Design in Public Systems); Section 3.5, Priority Sector 3 (Secure National Health Data Repository); Annex C, Healthcare and Life Sciences; Section 5, item 3.

    Comment / Suggestion: Introduce an explicit obligation, with a stated date and a phased schedule by provider size, for all healthcare providers contracted to the General Healthcare System (both public and private) to: (i) maintain structured electronic health records conforming to the European Electronic Health Record Exchange Format; and (ii) to transmit a defined minimum dataset to the National Health Data Repository. GHS contracting could be used as the enforcement mechanism.

    Justification: The Strategy describes a Secure National Health Data Repository that consolidates data from hospitals and laboratories, but places no obligation on the institutions that hold this data. Contribution will therefore be provided by hospitals that are willing to do so, and the national repository will only represent whoever choses to participate. Any AI system trained or validated on it will inherit that bias.

  27. Comment 5 of 8 from the German Medical Institute

    Comment 5: Name disease registries as first deliverables of the National Health Data Repository

    Article / paragraph: Section 3.5, Priority Sector 3 (Secure National Health Data Repository); Annex C, Healthcare and Life Sciences, “Implementation, evidence and compliance”; Section 3.2.1 (sectoral data spaces); Section 5, item 3.

    Comment / Suggestion: Specify a national cancer registry and a national rare disease registry as first outputs of the Secure National Health Data Repository. Each registry should have an identified responsible body and alignment to the corresponding European standards and infrastructures.

    Justification: The Secure National Health Data Repository is currently described by the data types it will consolidate (primary care, hospitals, laboratories, imaging, prescriptions) and not by any clinical product it will deliver. Disease registries are the natural first deliverable. They have a defined scope, an identifiable clinical owner, and an existing European reference framework. They are also where health AI development starts, because a curated registry with outcome data is a usable training and validation asset.

  28. Comment 4 of 8 from the German Medical Institute

    Comment 4: Recognise the European Network of AI-Powered Advanced Screening Centres in the international alignment provisions

    Article / paragraph: Annex C, Healthcare and Life Sciences, “International alignment”.

    Comment / Suggestion: Name the European Network of AI-Powered Advanced Screening Centres among the European initiatives in which Cyprus participates.

    Justification: Section 3.12.2 commits Cyprus to active participation in European initiatives, and the Healthcare pillar’s international alignment section in Annex C refers to WHO guidance and European principles. It would be good to mention the European Commission’s network on AI-Powered Advanced Screening Centres, which is the country’s most concrete existing operational link into European health AI practice and in which three Cypriot organisations are already members. The network is where deployment experience, evaluation methods and failure modes are exchanged between the hospitals doing this work within Europe.

  29. Comment 3 of 8 from the German Medical Institute

    Comment 3: Establish a national clinical AI validation function and require local performance verification before deployment

    Article / paragraph: Section 2.3.4 (Strengthening the International Position); Section 3.7.4 (Deployment Environments); Section 3.8.5 (National Testbeds); Annex C, Healthcare and Life Sciences, “Implementation, evidence and compliance”; Annex C, Entrepreneurship and Innovation (GHS health data sandbox).

    Comment / Suggestion: Add to the Healthcare pillar a requirement that no AI system be deployed in a publicly funded Cyprus clinical setting without a documented local performance evaluation. This should be conducted on local patient data and assessed against local clinicians’ reports. This should be repeated at defined intervals thereafter. Designate a national clinical AI validation function to publish the protocol, maintain the evidence base and make results available across the health system. CE marking is necessary for deployment but is insufficient alone.

    Justification: GMI can recommend this based on our own experience. In our chest X-ray programme we shortlisted candidate tools against published performance figures, then evaluated them on a consecutive sample of 731 local cases, using our radiologists’ original reports as the reference standard. Vendor-quoted metrics, obtained on the vendors’ test datasets, are not a reliable predictor of performance on a given hospital’s case mix. The evaluation changed which tool we selected. It is the single highest-value step in our deployment lifecycle and it cannot be substituted for with a CE mark. The CE mark certifies that a device meets its own intended-purpose claims, not that it performs on a particular population.
    There is a specific Cypriot obstacle that all hospitals wanting to perform local validation will encounter. The clinicians’ reports are in Greek and the AI outputs are in English, so local validation first requires translation before the reports could be used as the ground truth. Every Cypriot institution deploying diagnostic AI will meet the same problem and solving it once nationally is cheaper than solving it repeatedly for each centre.

  30. Comment 2 of 8 from the German Medical Institute

    Comment 2: Correct the compliance timeline and bring the regulatory components of the healthcare AI strategy forward to 2027

    Article / paragraph: Section 3.5, Priority Sector 3 (“A full-scale AI healthcare strategy is recommended for development by 2028”); Annex C, Healthcare and Life Sciences; Section 3.8.5 (National Testbeds); Section 5 (Immediate Steps); Annex A.

    Comment / Suggestion: Bring forward the regulatory, validation and conformity components of the dedicated AI healthcare strategy from 2028 to 2027. In parallel, state in Section 3.8.5 that Cyprus will satisfy its obligation under Article 57 of the AI Act to have at least one AI regulatory sandbox operational – this could be a healthcare sandbox. The responsible body and the date should be named.

    Justification: Since the Strategy was drafted, the dates for compliance have changed. Following adoption of the Digital Omnibus on AI by the European Parliament in June 2026 and the Council on 29 June 2026, the relevant dates are: Article 50 transparency obligations from 2 August 2026 (already in force); high-risk obligations for standalone Annex III systems from 2 December 2027; and high-risk obligations for AI embedded in regulated products from 2 August 2028. Separately, Member States must have at least one national AI regulatory sandbox in place by 2 August 2027.
    We also add that the European Health Data Space Regulation (EU) 2025/327 applies from 26 March 2027, with cross-border exchange of imaging, laboratory results and discharge reports required by March 2031. It also requires each Member State to designate a national digital health authority and a health data access body. These obligations should be included in the Strategy’s timeline.

  31. Comment 1 of 8 from the German Medical Institute

    Comment 1: Name the Medical Device Regulation in the Healthcare pillar and in the European alignment provisions

    Article / paragraph: Section 3.5, Priority Sector 3 (Healthcare and Life Sciences); Annex C, Healthcare and Life Sciences, “National frameworks and governance” and “International alignment”; Section 3.3.2 (Control Framework); Annex A (Alignment with European Legal and Policy Frameworks).

    Comment / Suggestion: Add Regulation (EU) 2017/745 on medical devices (MDR) and Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR) to Annex A and to the Healthcare pillar’s governance provisions. State explicitly that AI intended for diagnosis, triage, treatment decision support or patient risk stratification is regulated as a medical device, that CE marking under the MDR is a precondition of clinical deployment, and that EU AI Act obligations attach on top of that classification (and not in place of it). Require that every AI initiative in the Healthcare pillar carries a documented regulatory classification at the point it enters the national portfolio. If medical device are introduced, there should be clear documentation about its class and conformity assessment route.

    Justification: Under Rule 11 of Annex VIII to the MDR, software intended to provide information used to take decisions for diagnostic or therapeutic purposes is (at minimum) Class IIa. This rises to Class IIb where the decision may cause serious deterioration or require surgical intervention, and reaches Class III where it may cause death or irreversible deterioration. Applying that rule to the Strategy’s own intended infrastructures: (i) Intelligent Patient Triage and Care Navigation, which routes patients to care pathways including emergency services on the basis of clinical urgency, is not a low class device; (ii) Virtual AI Patient Orchestrator, which performs symptom reporting, risk alerts and referral, is also a medical device; (iii) the Socratic scaffolding will also be designing medical device diagnostic AI. Medical devices of Class IIa and above cannot be placed on the market without a notified body (self-declaration is not possible).

  32. SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY OF THE REPUBLIC OF CYPRUS 2032
    Comments on the Healthcare and Life Sciences pillar

    Submitted by: German Medical Institute (GMI), Limassol, Cyprus
    Date: 27/08/2026

    About the submitter
    The German Medical Institute is a hospital in Limassol and one of three Cypriot member organisations of the European Network of AI-Powered Advanced Screening Centres, convened by the Artificial Intelligence in Health and Life Sciences unit of the European Commission’s DG CNECT, alongside the State Health Services Organisation with the University of Cyprus, and the Bank of Cyprus Oncology Centre. On 11 May 2026 we presented our clinical AI deployment methodology to that network.
    We set out the following because several of the comments below rest on it:
    • GMI completed full hospital digitisation at the end of 2026.
    • Eight AI tools are in routine clinical use across radiotherapy, MRI, X-ray, nuclear medicine, dermatology and clinical document workflows, with further deployments in progress.
    • Every deployment follows a structured lifecycle that includes a local retrospective evaluation on our own patients, our own images and our own clinicians’ reports before any clinical use.
    • GMI is a partner in EU-funded work on the European Electronic Health Record Exchange Format (EEHRxF) and on cancer research data infrastructure under Horizon Mission Cancer.

    Declaration of interest. Through the GMI Innovation Centre we provide clinical validation and EU market-entry pathway support to international health-AI developers. This currently spans six programmes with developers in India, the United States, France and South Korea. We would therefore have an interest in national work of this kind, and several recommendations below, if adopted, would create opportunities for which we and other Cypriot institutions would be candidates. We make them because we consider the underlying gaps material, and we have stated at the end of this submission what we are offering without charge and what we are not.

    General remarks
    The Healthcare and Life Sciences pillar identifies the problems well: fragmented data, capacity pressure, and the need for clinical decision support that augments rather than displaces clinical judgement. The commitments to HL7 FHIR, SNOMED CT and ICD, to European Health Data Space principles, to independent Data Access Committees, and to monitoring for bias and model drift are the correct foundations.
    Our comments address one structural gap and seven consequences of it. The gap is that the Strategy governs healthcare AI almost entirely through the lens of the EU AI Act, which is mentioned throughout, and does not mention the Medical Device Regulation. For clinical AI, the Medical Device Regulation is the first step and the AI Act applies on top of it, not instead of it. Most of the flagship initiatives described in the Healthcare pillar are medical devices and thus the national programme should account for this.

  33. ΣΧΟΛΙΑ ΕΠΙ ΤΗΣ ΕΘΝΙΚΗΣ ΣΤΡΑΤΗΓΙΚΗΣ ΤΕΧΝΗΤΗΣ ΝΟΗΜΟΣΥΝΗΣ 2032
    1. Τεχνική ανακρίβεια στο ISO/IEC 42001
    Σε δύο τουλάχιστον σημεία (ενότητες 3.13.1 και 3.11.2), η Στρατηγική παρουσιάζει το ISO/IEC 42001 ως πρότυπο διαχείρισης κινδύνου (risk management). Δεν είναι. Το ISO/IEC 42001 αφορά το Σύστημα Διαχείρισης ΤΝ (AI Management System – AIMS), ενώ το ISO/IEC 23894 παρέχει καθοδήγηση ειδικά για τη διαχείριση κινδύνων ΤΝ (AI risk management). Η διάκριση είναι σημαντική και θα πρέπει να αποτυπωθεί σωστά στην τελική Στρατηγική.

    2. Η ήδη υπάρχουσα ΤΝ παραμένει αόρατη
    Ο AI Use Case Lifecycle (Annex B) και το AIREG δίνουν έμφαση κυρίως στη διακυβέρνηση και καταγραφή νέων ή υπό ανάπτυξη συστημάτων. Χρειάζεται όμως σαφέστερη πρόβλεψη και για την ΤΝ που ήδη χρησιμοποιείται, συχνά ενσωματωμένη σε ERP, CRM, SaaS ή διαδικασίες αυτοματοποιημένης λήψης αποφάσεων.
    Προτείνεται ένα συνεχώς ενημερωμένο μητρώο για όλα τα συστήματα ΤΝ στον δημόσιο τομέα, περιλαμβανομένων third-party και embedded AI, με σαφή καταγραφή του υπεύθυνου, του σκοπού χρήσης, του provider/model και του επιπέδου κινδύνου και αυτονομίας.
    Διαφορετικά, υπάρχει κίνδυνος να δημιουργήσουμε ένα ισχυρό πλαίσιο για το AI που έρχεται, χωρίς πλήρη εικόνα του AI που ήδη χρησιμοποιείται.

    3. Το Agentic AI χρειάζεται δικό του governance layer
    Η Στρατηγική αναφέρεται σε agentic AI, multi-agent systems, A2A, MCP και OASF, χωρίς όμως να ορίζει επαρκώς τι επιτρέπεται να κάνει ένα τέτοιο σύστημα. Χρειάζονται σαφείς κανόνες για permissions, tool access, memory, logging, human override και safe termination.
    Το Control Framework (Annex B) χρειάζεται να επεκταθεί ώστε να καλύπτει συστήματα που αναθέτουν υπο-εργασίες και εκτελούν ενέργειες αυτόνομα. Σε εφαρμογές όπως AI Judge, Virtual Patient Orchestrator ή agentic copilots στη ναυτιλία, το κρίσιμο ερώτημα δεν είναι μόνο «τι παράγει το σύστημα», αλλά «τι του επιτρέπεται να κάνει».

    4. Ο AI Officer δεν μπορεί να είναι ταυτόχρονα υλοποιητής και ελεγκτής
    Το Annex E αναθέτει στον AI Officer αρμοδιότητες τόσο στην υλοποίηση όσο και στη διαχείριση κινδύνου. Αυτό δημιουργεί πιθανή σύγκρουση ρόλων. Η υλοποίηση και η ανεξάρτητη αξιολόγηση ενός συστήματος θα πρέπει να παραμένουν διακριτές λειτουργίες, ώστε να αποφεύγεται πιθανή σύγκρουση συμφερόντων.
    Παράλληλα, η αναφορά ότι «deep technical expertise is not always required» χρειάζεται επανεξέταση, ιδιαίτερα για συστήματα υψηλού κινδύνου κατά το EU AI Act. Χρειάζεται ελάχιστο competency framework ανά επίπεδο κινδύνου, διαφανής διαδικασία επιλογής και, όπου υπάρχει ήδη η απαιτούμενη τεχνογνωσία στον δημόσιο τομέα, αξιοποίηση υφιστάμενου προσωπικού χωρίς κατ’ ανάγκη δημιουργία νέων θέσεων.

    5. Το human oversight χρειάζεται ορισμό στην πράξη και ανεξάρτητο έλεγχο για κρίσιμα συστήματα
    Η Στρατηγική δίνει σωστά έμφαση στο human oversight, χωρίς όμως να ορίζει πότε αυτό είναι ουσιαστικό στην πράξη. Ο άνθρωπος που φέρει την ευθύνη πρέπει να έχει τη γνώση, την πληροφόρηση, τον χρόνο και κυρίως την εξουσία να αμφισβητήσει, να ανατρέψει ή να σταματήσει μια ενέργεια του συστήματος. Διαφορετικά, το oversight κινδυνεύει να παραμείνει τυπικό.
    Για critical ή high-impact συστήματα, θα πρέπει επίσης να προβλέπεται ανεξάρτητη αξιολόγηση, ώστε ο έλεγχος να μην εξαρτάται αποκλειστικά από τον προμηθευτή ή τον φορέα υλοποίησης.

    6. Ετοιμότητα για σημαντικά πιο προηγμένα συστήματα ΤΝ στον ορίζοντα του 2032
    Η ενότητα 3.13.4 αναφέρεται σε «mechanisms to adapt», χωρίς όμως να καθορίζει συγκεκριμένους μηχανισμούς για σημαντικές αλλαγές στις δυνατότητες της ΤΝ. Δεν χρειάζεται η Στρατηγική να προβλέψει αν ή πότε θα υπάρξει AGI. Με ορίζοντα όμως το 2032, χρειάζεται να είναι έτοιμη για σημαντικά πιο ικανά ή αυτόνομα συστήματα.
    Προτείνεται capability-triggered review, με προκαθορισμένα thresholds που θα ενεργοποιούν αναθεώρηση όταν μεταβάλλονται ουσιαστικά οι δυνατότητες ή η αυτονομία των συστημάτων, όταν συμβαίνει σοβαρό AI incident ή όταν αλλάζει σημαντικά το regulatory environment. Ένας μόνο προγραμματισμένος κύκλος αναθεώρησης δεν αρκεί για μια τεχνολογία που εξελίσσεται με αυτή την ταχύτητα.

    7. Εκπαίδευση: από τη χρήση της ΤΝ στην ανθρώπινη κρίση
    Το CALF, το EPVL και το Socratic Scaffolding κινούνται στη σωστή κατεύθυνση. Θα έδινα όμως μεγαλύτερη έμφαση στην ανθρώπινη αυτενέργεια (Human Agency). Δεν αρκεί ο μαθητής να γνωρίζει πώς να χρησιμοποιεί την ΤΝ ή να υπάρχει ένας εκπαιδευτικός ως φίλτρο. Πρέπει σταδιακά να μάθει ο ίδιος να ορίζει τον σκοπό, να καθοδηγεί το σύστημα, να ζητά τεκμήρια, να επαληθεύει πηγές, να αναγνωρίζει αβεβαιότητα και να αμφισβητεί ακόμη και μια πολύ πειστική απάντηση.
    Όσο καλύτερα γίνονται τα συστήματα ΤΝ, τόσο σημαντικότερη γίνεται αυτή η ικανότητα. Ο στόχος δεν πρέπει να είναι μόνο Human-in-the-loop, αλλά Human-in-command: ο μαθητής να μπορεί να χρησιμοποιεί την ΤΝ χωρίς να της παραδίδει την κρίση του. Αυτή είναι δεξιότητα που θα παραμείνει σημαντική ανεξάρτητα από τα μοντέλα και τις τεχνολογίες που θα υπάρχουν το 2032.

    8. Τα KPIs δεν μπορούν να παραμείνουν «sample»
    Το Annex F χαρακτηρίζει το πλαίσιο των KPIs ως «sample». Αυτό χρειάζεται αλλαγή. Όταν η Στρατηγική θέτει συγκεκριμένους στόχους, όπως 75% AI adoption ή 10–20% μείωση κατανάλωσης καυσίμων στη ναυτιλία, πρέπει να είναι εξίσου συγκεκριμένος και ο τρόπος μέτρησής τους.
    Κάθε βασικό KPI χρειάζεται baseline, σαφή μεθοδολογία μέτρησης, υπεύθυνο φορέα και ετήσια δημόσια αναφορά προόδου. Διαφορετικά, στο τέλος θα γνωρίζουμε τους στόχους που τέθηκαν, αλλά όχι με αντικειμενικό τρόπο αν επιτεύχθηκαν. Η ευελιξία είναι χρήσιμη στην υλοποίηση, όχι στη λογοδοσία.

    9. Vendor lock-in και digital sovereignty
    Η Στρατηγική μιλά για digital sovereignty. Στην πράξη, όμως, το Δημόσιο πρέπει να μπορεί να αλλάξει AI provider χωρίς να εγκλωβίζεται σε μία εταιρεία ή πλατφόρμα.
    Χρειάζονται σαφείς απαιτήσεις για portability, interoperability και vendor exit, ώστε δεδομένα, μοντέλα και κρίσιμες λειτουργίες να μπορούν, όπου είναι τεχνικά εφικτό, να μεταφερθούν σε άλλον πάροχο. Για μια μικρή αγορά, η εξάρτηση από έναν πάροχο χωρίς πρακτική δυνατότητα εξόδου αποτελεί στρατηγικό κίνδυνο.

    10. Το «augment, not replace» πρέπει να μπορεί να μετρηθεί
    Η αρχή «augment, not replace» είναι σωστή ως κατεύθυνση, αλλά χρειάζεται μηχανισμό παρακολούθησης. Θα πρέπει να καταγράφεται ανά τομέα ποιες θέσεις ή καθήκοντα επηρεάζονται από την ΤΝ και πόσοι εργαζόμενοι επανακαταρτίζονται (re-skilling) ή μετακινούνται σε νέους ρόλους.
    Δεν αρκεί να λέμε ότι η ΤΝ θα ενισχύσει τον άνθρωπο. Πρέπει να μπορούμε και να το αποδεικνύουμε.

    11. Κάθε δημόσιος οργανισμός που χρησιμοποιεί ΤΝ πρέπει να έχει δική του AI Policy
    Η Στρατηγική θα ήταν χρήσιμο να προβλέπει ότι κάθε δημόσιος οργανισμός που αναπτύσσει ή χρησιμοποιεί ΤΝ διαθέτει γραπτή AI Policy. Η πολιτική αυτή πρέπει να καθορίζει τουλάχιστον πού και για ποιο σκοπό επιτρέπεται η χρήση ΤΝ, ποια είναι τα όρια, ποιος έχει την ευθύνη και ποιος λογοδοτεί.
    Αυτό συνδέεται και με το ISO/IEC 42001, το οποίο η ίδια η Στρατηγική επικαλείται και προβλέπει documented AI Policy στο πλαίσιο ενός AI Management System. Χωρίς σαφή πολιτική σε επίπεδο οργανισμού, οι υπόλοιποι μηχανισμοί governance δεν έχουν κοινή βάση εφαρμογής.

    12. Η ικανότητα κατεύθυνσης της ΤΝ χρειάζεται να ενταχθεί στις δεξιότητες
    Η Στρατηγική προβλέπει agentic AI, multi-agent systems και σύνθετες εφαρμογές ΤΝ σε κρίσιμους τομείς. Δεν δίνεται όμως αντίστοιχη έμφαση στην ικανότητα του ανθρώπου να κατευθύνει αποτελεσματικά αυτά τα συστήματα: να ορίζει σκοπό, να παρέχει το κατάλληλο context, να θέτει περιορισμούς και να αξιολογεί αν το αποτέλεσμα ανταποκρίνεται στην πρόθεσή του.
    Δεξιότητες όπως prompt engineering και context engineering, ανεξάρτητα από το πώς θα ονομάζονται στο μέλλον, θα πρέπει να ενταχθούν στα σχετικά εκπαιδευτικά και επαγγελματικά πλαίσια. Όσο πιο ικανά γίνονται τα συστήματα ΤΝ, τόσο πιο σημαντική γίνεται η ικανότητα του ανθρώπου να τους δίνει σωστή κατεύθυνση.

    13. Η κυβερνοασφάλεια πρέπει να ενσωματωθεί στον κύκλο ζωής κάθε συστήματος ΤΝ
    Η Στρατηγική δίνει σημαντική έμφαση στην κυβερνοασφάλεια, αλλά χρειάζεται σαφέστερη σύνδεσή της με τον AI Use Case Lifecycle (Annex B). Κάθε σύστημα ΤΝ, ιδιαίτερα σε κρίσιμες λειτουργίες, θα πρέπει να περνά υποχρεωτικό security assessment πριν τεθεί σε παραγωγική λειτουργία και να επανελέγχεται όταν αλλάζει ουσιαστικά.
    Ιδιαίτερη πρόβλεψη χρειάζεται για agentic AI, όπου εμφανίζονται νέοι κίνδυνοι όπως prompt injection, tool poisoning και memory manipulation. Η κυβερνοασφάλεια δεν πρέπει να λειτουργεί παράλληλα με το AI governance, αλλά να αποτελεί μέρος του ίδιου του κύκλου ζωής του συστήματος.

Αφήστε μια απάντηση

Back to top button
Μετάβαση στο περιεχόμενο